Platform & Code (PC3)
Platform & Code
3
Harold can expose sensitive data displayed, entered, or cached because the data is excessive, not properly masked or cleared after use, persisted without protection, exposed to web content, or made available to third-party components through unnecessary permissions
Scenario: Harold can expose sensitive data displayed, entered, or cached because the data is excessive, not properly masked or cleared after use, persisted without protection, exposed to web content, or made available to third-party components through unnecessary permissions
Example
Threat Modeling
STRIDE
What can go wrong?
What are we going to do about it?
Mappings
STRIDE: -
MASTG: 0316,0320,0346,0347,0378,0390
MASTG Best: 0028,0044,0059,0060,0069
MASTG Know: 0018,0121,0141,0076,0139,0082
CAPEC™: 508
SAFECode™: -
MASVS: MASVS-PLATFORM-3,MASVS-STORAGE-2,MASVS-STORAGE-1,MASVS-CRYPTO-2,MASVS-PLATFORM-2,MASVS-CODE-4,MASVS-PRIVACY-1
No attacks registered!