Table 8.
Assetid (Data-Level, Data-Phase) |
Threats (Criticality) |
Controls | Assurance Level (Ct, Ef, Cx) → OAL |
---|---|---|---|
Net3 (mD, Dp) | CAPEC-151 (VH) |
IA-2(1)-Identification Additionally, Authentication [38] | (H, H, M) → 8 (H) |
Net3 (bD, Dt) | CAPEC-125 (VH) |
SC-5(3)-Denial-Of-Service Protection [38] | (H, M, L) → 8(H) |
App0 ((bD, mD), Dp) | CAPEC-151 (VH) |
IA-2(1)-Identification Additionally, Authentication [38] | (H, H, M) → 8 (H) |
App0 (bD, Dp) | CAPEC-63 (VH) |
SI-10(5)-Information Input Validation [38] | (H, H, L) → 9 (H) |