Skip to main content
Guidance

Building a Security Operations Centre (SOC)

Designing a security monitoring capability proportionate to the threats faced (and resources available).

Page 8 of 14

Threat modelling

Note:

It's also important to remember that this approach will not immediately highlight the emergence of risks across the system. This is simply about getting the appropriate log sources into your SOC systems, at which point system-wide risks can be considered. See Detection for more information on identifying system-wide risks.

With the caveat that there are many ways to perform threat modelling, this is simply a guide on how to start a component level analysis. It loosely follows an attack tree methodology, but has a focus on identifying the most valuable log sources and appropriate detection use-cases.

Threat modelling process

An image of a flow chart showing the threat modelling process. Component - Risk - Actor - Attack - Log Source - Detection

The diagram above depicts the process that will enable an organisation to methodically analyse a system for potential risks, identifying attack vectors and log sources. This information can then also be used as a basis for creating a suite of detections. We explore each step in detail below.
 


Published

Reviewed

Version

1.0