PTES
Threat Modeling

PTES PTESPHASE-3: Threat Modeling

Per PTES Threat Modeling phase: model threats. Requirements include (a) identify threat agents relevant to target including external + internal + nation-state + criminal + (b) model attack scenarios + paths + (c) determine motivations + capabilities + (d) align scenarios to engagement objectives + (e) document threat model + (f) integrate with vulnerability analysis + exploitation.

What else in your programme already covers this

This control maps to 194 controls across 69 other frameworks. If you already hold one of them, the evidence you collected for it is the starting point here rather than new work.

NIST SP 800-53 Rev 5 · 8 controls

  • ASD37-06 Email content filtering (Excellent)
  • ASD37-12 Antivirus software with heuristics (Very Good)
  • ASD37-16 Antivirus software with signatures (Limited)
  • ASD37-17 TLS encryption between email servers (Limited)
  • ASD37-34 Regular backups (Essential)
  • ASD37-35 Business continuity and disaster recovery plans (Very Good)
  • ASD37-36 System recovery capabilities (Very Good)

ISO 27043 · 7 controls

ISO/SAE 21434 · 7 controls

  • 3.3.1 SAD is not stored after authorization, even if encrypted. All sensitive authentication data received is rendered unrecoverable upon completion of the authorization process
  • 3.6 Encrypt Data on End-User Devices
  • FEDRAMP-CP-9 System Backup
  • FEDRAMP-SC-13 Cryptographic Protection
  • FEDRAMP-SC-28 Protection of Information at Rest
  • FEDRAMP-SC-8 Transmission Confidentiality and Integrity

API 1164 · 4 controls

BSI IT-Grundschutz · 4 controls

  • BSI-08 Cryptographic protection of data
  • BSI-28 Audit event logging and storage
  • BSI-29 Audit record review and analysis
  • BSI-31 Audit log protection and retention

IEC 62443 · 4 controls

ISO 27019 · 4 controls

ISO/IEC 27011:2024 · 4 controls

NIST SP 1800-32 · 4 controls

South Korea ISMS-P · 4 controls

  • CJIS-10 System and Information Integrity
  • CJIS-8 Media Protection
  • CJIS-9 System and Communications Protection

ISO 13485 · 3 controls

ISO 27017 · 3 controls

ISO 27018 · 3 controls

ISO 27799 · 3 controls

ISO/IEC 27031:2011 · 3 controls

  • NIST-CSF-RC.RP-01 The recovery portion of the incident response plan is executed once initiated from the incident response process
  • NIST-CSF-RC.RP-06 The end of incident recovery is declared based on criteria, and incident-related documentation is completed
  • NIST-CSF-RS.MA-05 The criteria for initiating incident recovery are applied

NIST SP 800-190 · 3 controls

  • 6.6 Confidentiality or non-disclosure agreements
  • 6.7 Conducting Audit Follow-up

ISO 19011 · 2 controls

  • 6.6 Confidentiality or non-disclosure agreements
  • 6.7 Conducting Audit Follow-up

ISO 22316 · 2 controls

ISO 22317 · 2 controls

ISO 22318 · 2 controls

ISO 31000:2018 · 2 controls

  • 6.6 Confidentiality or non-disclosure agreements
  • 6.7 Conducting Audit Follow-up

ISO/IEC 27010:2015 · 2 controls

OWASP SAMM · 2 controls

  • OWASPSAMM-2 Design: Threat Assessment, Security Requirements, Security Architecture
  • OWASPSAMM-5 Operations: Incident Management, Environment Management, Operational Management

PCI P2PE · 2 controls

PCI PIN Security · 2 controls

PCI SSF · 2 controls

APPI · 1 control

  • APPI-A34 Request for Correction, Addition or Deletion
  • 4.4.8 Business Continuity and Recovery

Bahrain PDPL · 1 control

  • DIQ-1 Data Integration and Interoperability

FIDO2 / WebAuthn · 1 control

  • FTC-Safeguards-9-Elements 9 Safeguard Elements - Access, Inventory, Encryption, Secure-Dev, MFA, Disposal, Change-Mgmt, Monitoring, Pen-Test (16 CFR 314.4(c))
  • UAE-PDPL-Art.4_5 Lawful basis and principles for processing personal data (UAE PDPL Articles 4-5)

ISO 20000-1 · 1 control

  • 9.1 Risk communication and consultation

ISO 22320:2018 · 1 control

ISO 27005 · 1 control

  • 9.1 Risk communication and consultation

ISO/IEC 27400:2022 · 1 control

  • STANAG-2 STANAG 4778 Metadata Binding Mechanism and Cryptographic Binding

NIST SP 800-171 · 1 control

  • 3.3.1 SAD is not stored after authorization, even if encrypted. All sensitive authentication data received is rendered unrecoverable upon completion of the authorization process

PSD2 SCA · 1 control

  • PSDTWO-2 SCA Exemptions and Risk-Based Authentication

Qatar DPL · 1 control

Turkey KVKK · 1 control

Vietnam PDPD · 1 control

Every mapping shown was judged rather than inferred from wording similarity, and the ones that failed review are published too. See the coverage reports and what was rejected.

Query this from an agent

The graph holds this control, the 194 it maps to, and the evidence behind each claim, over MCP and REST.