In a STRIDE threat model, how do you find the threats that were left with no control at all?
answer
- absence is invisible in prose
- rows and a column, not paragraphs
- an empty mitigation cell is a finding
- one control against ten rows is suspicious
- actors with legitimate access hide here
basics
~20 sTreat the mapping as a table, not prose: every enumerated threat is a row, and before the session closes you filter for blank mitigation cells and for one control claiming many rows. Gaps cluster where no familiar control family applies.
solid answer
~50 sAbsence is invisible in prose, so the mapping pass has to be structured - threats as rows, controls as a column - and the sweep is mechanical: filter for empty mitigation cells, then take any control written against many rows and check per row that the attack really fails with it. The more interesting part is knowing where gaps cluster. A threat gets skipped when no control family the team routinely reaches for applies to it, and actors with legitimate access are the classic case: a genomics platform can find everything else covered while 'a researcher copies a whole dataset to a personal laptop' has nothing next to it, because authentication, authorization and encryption all pass and none of them stop an approved user. An uncovered threat leaves the session with an owner, never as a blank.
go deeper
Know that every enumerated threat needs an entry and that a blank mitigation is something to raise, not a row to quietly skip past.
Explain the sweep mechanically: threats as rows, controls as a column, filter for blanks, and question any single control that claims many rows before the session closes.
Show where gaps cluster in real models - actors with legitimate access, and threats to availability or to the trustworthiness of records - and how you surface them rather than pasting in a nearby control.
Own what happens to an uncovered threat after the meeting: who receives it, in which record it lives, and how the next iteration re-reads those rows instead of silently inheriting the blank.
## Why gaps hide A wrong control is at least visible: someone wrote something, and a reviewer can argue with it. A missing control is invisible, because nothing is there to look at. If the mapping is written as prose - a paragraph per area saying how the design is secured - absence has nowhere to show up, and a threat that nobody could answer simply drops out of the narrative between two sentences. That is the whole reason this pass is structured. Enumerated threats become rows; the mitigation is a column; and the question 'what has nothing?' becomes a filter rather than an act of memory. ## The mechanical sweep Before the session closes, two passes take a few minutes each. **Filter for blanks.** Every enumerated threat must carry an entry. If the cell is empty, that is a finding in its own right - the model's most valuable output, not an embarrassment to be tidied away. **Look at cardinality.** The relationship between threats and controls is many-to-many, and both directions carry signal. One control written against ten rows is sometimes genuine - a single platform-level enforcement really can close ten variants of the same move - but it is just as often a row filled to look covered. Check per row that the attack actually fails with that control assumed. Equally, a threat that needs five controls stacked to be closed is telling you something about how fragile that part of the design is. A third, cheaper heuristic: compare the count of threats enumerated against the count of distinct controls named. A model with forty threats and four controls has usually not done the mapping; it has written a security overview. ## Where gaps actually cluster The sweep tells you a row is empty. Experience tells you which rows to expect to be empty, and this is what separates a mechanical pass from a useful one. **Threats from actors with legitimate access.** This is the biggest one. A genomics research platform runs its mapping pass and finds a control against nearly everything: credentials, session handling, access control on datasets, encryption of stored genomes, protection of the analysis pipeline. Then there is one row - a researcher with approved access to a dataset copies it in bulk to a personal laptop - and nothing is written next to it. Not because it was judged unimportant: because every family the team knows how to reach for has already been applied and none of them fire. Authentication succeeds. Authorization succeeds. The data is decrypted for exactly the person who is allowed to decrypt it. The asset at stake here is trade-secret research value and the personal data of study participants, and the model's usual vocabulary has run out. The honest answers to that row are all partial, and saying so is the point: per-dataset entitlements so approval is granular rather than blanket; de-identified or synthetic extracts for exploratory work so full copies are rarely needed; analysis-in-place workspaces that make bulk export an exceptional operation rather than a normal one; egress volume monitoring as a detective backstop with a defined response; and administrative measures like agreements and training. None of those is a clean stop. Writing all of them down, with their limits, is a genuinely better model than writing nothing. **Threats to properties other than confidentiality.** Teams have a rich vocabulary for keeping secrets and a much thinner one for keeping a service available or keeping records trustworthy. Those rows go blank disproportionately often. **Threats at the far end of a flow.** The parts of the diagram drawn in the least detail produce the threats with the least specific answers, and vague threats attract vague controls or none. ## False coverage looks the same as coverage Worth naming explicitly: a blank cell is often filled at the last minute with the nearest plausible control, precisely so the table looks complete. That produces a row that reads as covered and is not. If a control appears against a threat it has no obvious relationship to, treat it as a suspected gap rather than an entry - the sweep for blanks and the check that a control genuinely answers its threat are two halves of the same pass. ## What happens to a gap An uncovered threat is not a failure of the model; it is the model working. What matters is that it leaves the room as a tracked item - written down, owned by a named person, and re-read at the next iteration - and gets handed to whoever makes the call about what to do with it. A blank that nobody carried forward is the same as a threat never found.
- A researcher copies an approved dataset to a personal laptop. Which control classes even apply?All of them partial, which is the honest answer. Per-dataset entitlements so approval is granular rather than blanket; de-identified or synthetic extracts so full copies are rarely needed; analysis-in-place workspaces that make bulk export exceptional rather than routine; egress volume monitoring with a defined response as a detective backstop; plus administrative measures. Writing those down with their limits beats leaving the row blank or pretending access control covers it.
- One control is written against ten different threat rows. How do you react?Check it per row rather than accepting or rejecting it wholesale. A genuine platform-level enforcement can close ten variants of the same move, and that is a good outcome. But it is equally often a row filled to make the table look complete, so I assume the control is working and re-run each of the ten attacks; the ones that still complete were never covered.
- How do you stop the gap list from evaporating after the session ends?Each uncovered threat leaves the room as a tracked item with a named owner and a record, and it goes to whoever makes the call about what to do with it. The next iteration of the model re-reads those rows first. A blank that nobody carried forward is indistinguishable from a threat that was never found.
A packing list only works because someone counts the bags against it at the door. A list nobody counts back against is decoration, and the missing bag is discovered at the destination.
saying these in an interview costs you the question
- Writes the mapping as prose, where absence cannot show up
- Treats an empty mitigation cell as untidy rather than a finding
- Fills blanks with the nearest plausible control before publishing
- Accepts one control claiming many threat rows unchecked
- Assumes access control covers misuse by an approved user
- Lets uncovered threats leave the session with no owner