X.805 Clause 8 defines 5 Threat Categories that the X.805 Security Architecture is designed to mitigate + provides a Threat-Dimension Countermeasure Matrix linking each threat to specific Dimensions. (1) The 5 X.805 Threat Categories per X.805 Clause 8 + X.800 + ISO/IEC 7498-2 Heritage: (a) DESTRUCTION of information and/or other resources - the targeted resource is permanently destroyed + cannot be recovered (without restoration mechanisms); examples - disk wipe + media destruction + nuke malware + Stuxnet + Shamoon + NotPetya + Olympic Destroyer + Wiper malware; (b) CORRUPTION or modification of information - the resource is altered + falsified + tampered with; examples - data tampering + log alteration + man-in-the-middle modification + BGP route manipulation + DNS cache poisoning + database update without authorization; (c) REMOVAL of information and/or other resources (e.g. theft) - the resource is illegitimately taken from its owner; examples - data exfiltration + IP theft + hardware theft + cryptocurrency theft + ransomware + APT exfiltration + supply chain theft; (d) DISCLOSURE of information - the resource information is exposed to unauthorized parties; examples - eavesdropping + sniffing + side-channel + data breach + unsecured S3 bucket + insider leak + traffic analysis + metadata leak + SQL injection; (e) INTERRUPTION of services - service availability is degraded or removed; examples - DoS + DDoS + Ransomware + power outage + natural disaster + accidental misconfiguration + software bug + supply chain disruption + insider sabotage. (2) Threat-Dimension Countermeasure Matrix per X.805 Table 1: An 8 x 5 matrix mapping which Security Dimensions counter which Threats. Each cell marked Y indicates the Dimension is effective against that Threat. (a) Access Control - Y/Y/Y/Y/Y (counters all 5); (b) Authentication - blank/Y/blank/Y/Y (Corruption + Disclosure + Interruption); (c) Non-Repudiation - Y/Y/Y/Y/Y (all 5 via audit evidence); (d) Data Confidentiality - blank/blank/Y/Y/blank (Removal + Disclosure); (e) Communication Security - blank/blank/Y/Y/blank (Removal + Disclosure); (f) Data Integrity - blank/Y/Y/blank/blank (Corruption + Removal); (g) Availability - Y/blank/blank/blank/Y (Destruction + Interruption); (h) Privacy - blank/blank/blank/Y/blank (Disclosure only - distinct from Confidentiality). (3) 72-Cell Matrix Application: X.805 instructs that for each of the 9 (Layer x Plane) Modules + the 8 Security Dimensions must be applied (giving 72 Security Perspectives) + for EACH of the 72 cells + the 5 Threats must be evaluated. This yields a comprehensive 9 x 8 x 5 = 360-cell security risk + countermeasure assessment per network architecture. (4) X.805 Threats vs Other Threat Models: (a) STRIDE (Microsoft Threat Modelling) - Spoofing + Tampering + Repudiation + Information Disclosure + Denial of Service + Elevation of Privilege - maps to X.805 Threats with Authentication countering Spoofing + Integrity countering Tampering + Non-Repudiation countering Repudiation + Confidentiality countering Information Disclosure + Availability countering DoS + Access Control countering Elevation of Privilege; (b) MITRE ATT and CK Tactics - Initial Access + Execution + Persistence + Privilege Escalation + Defense Evasion + Credential Access + Discovery + Lateral Movement + Collection + Command and Control + Exfiltration + Impact - X.805 Threats align with Impact (Destruction/Corruption/Removal/Disclosure/Interruption); (c) DREAD scoring - Damage + Reproducibility + Exploitability + Affected Users + Discoverability; (d) OCTAVE - Operationally Critical Threat Asset Vulnerability Evaluation; (e) FAIR Factor Analysis of Information Risk; (f) NIST SP 800-30 Risk Assessment. (5) Network-Specific Threat Examples per X.805 Architecture: (a) Infrastructure / Management / Destruction - rogue admin destroys configuration backups; (b) Infrastructure / Control / Corruption - BGP route hijacking redirects traffic; (c) Infrastructure / End-User / Disclosure - fibre tap captures subscriber data; (d) Services / Management / Removal - subscriber database exfiltration; (e) Services / Control / Interruption - SIP signalling flood DoS; (f) Services / End-User / Disclosure - DNS query analysis reveals user activity; (g) Applications / Management / Corruption - configuration management system tampering; (h) Applications / Control / Disclosure - API key leakage; (i) Applications / End-User / Removal - user data exfiltration via XSS. (6) Threat Application Methodology per X.805: (a) Identify all 9 Modules (Layers x Planes) in scope; (b) For each Module identify the 8 Dimension implementations + gaps; (c) For each Module evaluate each of the 5 Threats; (d) For each Threat in each Module identify Countermeasures from the relevant Dimensions; (e) Risk score the residual exposure; (f) Plan + implement countermeasure improvements; (g) Re-assess. (7) Modern Evolution: (a) Threat Modelling tools (Microsoft TMT + OWASP Threat Dragon + IriusRisk + ThreatModeler); (b) Continuous Threat Modelling per DevSecOps; (c) Threat Intelligence Platforms (TIP) + MISP + OpenCTI + Anomali + ThreatConnect; (d) Cyber Threat Intelligence (CTI) sharing standards STIX 2.1 + TAXII 2.1; (e) MITRE D3FEND complement to ATT and CK; (f) MITRE ATLAS adversarial ML threats; (g) Threat Hunting + Purple Teaming + Red Team + Blue Team; (h) AI-powered threat detection + SOC; (i) Quantum threats + Harvest Now Decrypt Later + Q-Day preparation. Coordinates with X.805 Layer 1/2/3 + Plane 1/2/3 + 8 Dimensions + ISO/IEC 27005 Risk Management + ISO/IEC 27035 Incident Management + NIST SP 800-30 Risk Assessment + 800-37 RMF + ISO 31000 + STRIDE + MITRE ATT and CK + MITRE D3FEND + MITRE ATLAS + DREAD + OCTAVE + FAIR + STIX 2.1 + TAXII 2.1 + ITU-T X.1500-Series Cybersecurity + 3GPP TS 33.117 SCAS + ETSI TS 102 165 TVRA. ITU-T X.805 Threats + Application Methodology applies.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.