• xThreat Vector: Spoofing
IDNameBaselinesPriorityThreats
LowModerateHigh
AC-2Account Management
  • P1
STRIDE-LM
(1)Automated System Account Management 
  • P1
STRIDE-LM
(2)Removal Of Temporary / Emergency Accounts 
  • P1
STRIDE-LM
(3)Disable Inactive Accounts 
  • P1
STRIDE-LM
(4)Automated Audit Actions 
  • P1
STRIDE-LM
(5)Inactivity Logout  
  • P1
STRIDE-LM
(6)Dynamic Privilege Management   
  • P1
STRIDE-LM
(8)Dynamic Account Creation   
  • P1
STRIDE-LM
(12)Account Monitoring / Atypical Usage  
  • P1
STRIDE-LM
AC-4Information Flow Enforcement 
  • P1
STRIDE-LM
(1)Object Security Attributes   
  • P1
STRIDE-LM
(2)Processing Domains   
  • P1
STRIDE-LM
(3)Dynamic Information Flow Control   
  • P1
STRIDE-LM
(4)Content Check Encrypted Information   
  • P1
STRIDE-LM
(7)One-Way Flow Mechanisms   
  • P1
STRIDE-LM
(8)Security Policy Filters   
  • P1
STRIDE-LM
(9)Human Reviews   
  • P1
STRIDE-LM
(12)Data Type Identifiers   
  • P1
STRIDE-LM
(13)Decomposition Into Policy-Relevant Subcomponents   
  • P1
STRIDE-LM
(17)Domain Authentication   
  • P1
STRIDE-LM
AC-7Unsuccessful Logon Attempts
  • P2
STRIDE-LM
AC-9Previous Logon (Access) Notification   
  • P0
STRIDE-LM
(3)Notification Of Account Changes   
  • P0
STRIDE-LM
AC-10Concurrent Session Control  
  • P3
STRIDE-LM
AC-11Session Lock 
  • P3
STRIDE-LM
AC-12Session Termination 
  • P2
STRIDE-LM
AC-24Access Control Decisions   
  • P0
STRIDE-LM
AU-6Audit Review, Analysis, And Reporting
  • P1
STRIDE-LM
(3)Correlate Audit Repositories 
  • P1
STRIDE-LM
(5)Integration / Scanning And Monitoring Capabilities  
  • P1
STRIDE-LM
(6)Correlation With Physical Monitoring  
  • P1
STRIDE-LM
(9)Correlation With Information From Nontechnical Sources   
  • P1
STRIDE-LM
IA-2Identification And Authentication (Organizational Users)
  • P1
STRIDE-LM
(1)Network Access To Privileged Accounts
  • P1
STRIDE-LM
(2)Network Access To Non-Privileged Accounts 
  • P1
STRIDE-LM
(3)Local Access To Privileged Accounts 
  • P1
STRIDE-LM
(4)Local Access To Non-Privileged Accounts  
  • P1
STRIDE-LM
(6)Network Access To Privileged Accounts - Separate Device   
  • P1
STRIDE-LM
(7)Network Access To Non-Privileged Accounts - Separate Device   
  • P1
STRIDE-LM
(8)Network Access To Privileged Accounts - Replay Resistant 
  • P1
STRIDE-LM
(9)Network Access To Non-Privileged Accounts - Replay Resistant  
  • P1
STRIDE-LM
IA-3Device Identification And Authentication 
  • P1
STRIDE-LM
(1)Cryptographic Bidirectional Authentication   
  • P1
STRIDE-LM
(3)Dynamic Address Allocation   
  • P1
STRIDE-LM
(4)Device Attestation   
  • P1
STRIDE-LM
IA-4Identifier Management
  • P1
STRIDE-LM
(1)Prohibit Account Identifiers As Public Identifiers   
  • P1
STRIDE-LM
(3)Multiple Forms Of Certification   
  • P1
STRIDE-LM
(4)Identify User Status   
  • P1
STRIDE-LM
(5)Dynamic Management   
  • P1
STRIDE-LM