STRIDE · ETSI TS 102 165-1

STRIDE threat modeling with ETSI risk scoring

STRIDE tells you what can go wrong. ETSI TS 102 165-1 tells you how much it matters. Zybercomply uses both together so every threat ends up with a consistent, explainable risk rating.

The six STRIDE categories

  • Spoofing — pretending to be another user or device
  • Tampering — changing data or firmware without authorisation
  • Repudiation — denying an action because it was not logged
  • Information disclosure — exposing data to the wrong party
  • Denial of service — making the product unavailable
  • Elevation of privilege — gaining rights you should not have

Scoring with ETSI TS 102 165-1

Each threat gets a likelihood and an impact on a 1–5 scale. Likelihood weighs factors such as attacker expertise, required equipment and window of opportunity; impact weighs the consequence for the asset. Their product places the threat in the risk matrix, and a residual score is recorded once mitigations are in place.

Why combine them

STRIDE gives systematic coverage per asset; ETSI scoring makes the results comparable and auditable. Together they produce the risk register and treatment decisions that standards such as prEN 40000-1-2 expect.