Risk analysisRisk analysis\Threats\Identification

Identification

Quick start

Select automatic threats in Options / Threats

 

This section explains the behaviour for manual mode. If it is automatic, most options are disabled since PILAR automatically applies the standard values from the TSV file.

NOTE. If Options / Threats are set to automatic, then some buttons are disabled:

§  apply and remove

§  undo / redo

§  cancel and close

Let us identify which threats are possible for each asset.

 

Top menu TSV

TSV

See “Threat Standard Values

 

Top toolbar

Spinner to control the expansion of the assets tree.

+1

Adjust the effect of the spinner [2].

If +1 is checked, PILAR shows the threats associated to an asset. If unchecked, the threats are not expanded.

threats

    Select one or more assets in the left panel ([8]).

    Click THREATS.

PILAR selects on the right panel ([9]) the threats that are associated to the selected assets.

Spinner to control the expansion of the threats tree.

assets

    Select one or more threats in the right panel ([9]).

    Click ASSETS.

PILAR selects on the left panel ([8]) the assets that are associated to the selected threats.

 

Bottom toolbar

:::IdeaProjects:renata_52:util:imgs:26x26:undo.png

Undo last association of threats to assets.

:::IdeaProjects:renata_52:util:imgs:26x26:redo.png

Redo last undone association of threats to assets.

apply

    Select one or more assets in the left panel ([8]).

    Select one or more threats in the right panel ([9]).

    Click APPLY t

PILAR associates the selected threats to the selected assets.

remove

    Select one or more assets in the left panel ([8]).

    Select one or more threats in the right panel ([9]).

    Click REMOVE.

PILAR dissociates the selected threats to the selected assets.

Or

    Select one or more threats in the left panel ([8]).

    Click REMOVE

PILAR dissociates the selected threats from the associated assets.

:::IdeaProjects:renata_52:util:imgs:16x16:save.png

Saves current project either in a file, or in database (according to its source).

 

On assets (left panel)

·       Right click > CURRENT

·       to select current threats on the right panel

·       Right click > STANDARD

·       to select threats on the right panel (those in TSV, but optional ones)

·       Right click > OPTIONAL

·       to select threats on the right panel (those in TSV marked as optional)

 

Options / Threats are set to automatic.

Some buttons are disabled:

§  apply and remove

§  undo / redo

§  cancel and close

Options / Threats are set to manual.

§  Apply and remove buttons are enabled.

§  TSV is not applied by default

Options / Threats are set to mix.

§  Apply and remove buttons are enabled.

§  TSV is not applied by default

 

In manual mode and mix modes, you can associate threats to assets freely.

To assign TSV threats to an asset
(or a group, or a layer, or all of them)

·       select asset(s), group(s), layer(s), or top node

·       top menu TSV > apply

 

 

To assign a threat to an asset

·       select the asset on the left (one or more)

·       select the threat on the right (one or more)

·       click APPLY

To remove a threat from an asset

·       select the asset on the left (one or more)

·       select the threat on the right (one or more)

·       click REMOVE

or

·       select the threat on the left (one or more)

·       click on REMOVE

Which threats are associated to an asset?

·       select the asset on the left

·       right click > CURRENT

Which threats are associated to an asset as standard?

·       select the asset on the left

·       right click > STANDARD

Which threats are optionally associated to an asset?

·       select the asset on the left

·       right click > OPTIONAL

To "copy and paste" threats from an asset onto another

·       select the source asset on the left

·       click THREATS to select on the right

·       select the destination asset on the left (one or more)

·       click APPLY

Which assets are subject to a threat?

·       select the threat on the right (one or more)

·       click ASSETS

 

Top