skip to content

Methodologies Beyond STRIDE

The major alternatives to STRIDE — risk-centric PASTA, privacy-focused LINDDUN, organizational OCTAVE Allegro — and the trade-offs that decide which fits a team. Interviewers want a justified choice.

on this pageshow

explore

questions

28

What are the seven LINDDUN threat types, and which privacy property does each one break?

level: middleimportance: must knowfreq 72%

answer

  1. Seven types, one per privacy property
  2. Each letter negates something you wanted
  3. Two different N's, don't merge them
  4. Existence hidden versus content hidden
  5. One type sits on the person, not a component

basics

~10 s

LINDDUN covers Linkability, Identifiability, Non-repudiation, Detectability, Disclosure of information, Unawareness and Non-compliance. Each names the failure of a privacy property: unlinkability, anonymity, plausible deniability, undetectability, confidentiality, user awareness, and policy compliance.

solid answer

~40 s

LINDDUN is a privacy threat modeling method whose seven letters are threat types, each the negation of a privacy property. Linkability breaks unlinkability: you can tell two items concern the same person. Identifiability breaks anonymity: you can pin an item to a named individual. Non-repudiation breaks plausible deniability: someone cannot deny having acted. Detectability breaks undetectability: you can tell a record exists even without reading it. Disclosure of information breaks confidentiality. Unawareness breaks the subject's understanding and control of what is shared about them. Non-compliance breaks the system's own stated policy for how data is handled. Current LINDDUN material relabels several of these as Linking, Identifying, Detecting, Data Disclosure and Unawareness & Unintervenability, but the seven categories are the same. The list is a categorisation of threats, not a severity rating.

go deeper

for a junior

Be able to say LINDDUN is the privacy counterpart to a security threat-category method, and that it has seven threat types aimed at protecting the person whose data is processed rather than the system.

for a middle

Expect to list all seven and name the privacy property each negates, and to explain the pairs people confuse: linkability versus identifiability, and detectability versus disclosure.

for a senior

Show that you use the list to drive a real design conversation — which types actually bite on the system in front of you, and why the ones that survive encryption are usually the interesting ones.

for a principal

Own the framing question: what does adopting a privacy threat taxonomy commit the organisation to, given it produces categorised threats but no ratings and no legal conclusions, and who consumes that output.

## What LINDDUN is LINDDUN is a privacy threat modeling methodology developed by the DistriNet research group at KU Leuven. Structurally it works the way STRIDE does: you take a model of the system, walk its elements, and ask a fixed list of threat categories against each one. What changes is the asset. A security pass protects the system and its owner; LINDDUN protects the **data subject** — the person whose data the system processes — and the party you are modeling against may be someone with entirely legitimate access. The acronym is seven **threat types**. Each is the mirror image of a privacy property, so the fastest way to remember the list is to remember the properties and negate them. | Threat type | Property it breaks | Reading in one line | | --- | --- | --- | | **L**inkability | Unlinkability | Two items can be told to concern the same subject, without necessarily knowing who | | **I**dentifiability | Anonymity / pseudonymity | An item can be tied to a specific individual | | **N**on-repudiation | Plausible deniability | A person cannot credibly deny having done something | | **D**etectability | Undetectability / unobservability | The existence of an item can be distinguished, even if its content stays hidden | | **D**isclosure of information | Confidentiality | The content itself is exposed to someone not entitled to it | | **U**nawareness | Content awareness and intervenability | The subject does not understand, or cannot control, what is shared about them | | **N**on-compliance | Policy and consent compliance | Processing departs from the policy the system itself states | ## The distinctions that get probed **Linkability versus identifiability.** Linkability is the weaker, earlier condition: given two records you can say "same person" without knowing the name. Identifiability is the stronger one: you can say *which* person. Most real privacy failures are a linkability chain that ends in identifiability, because a pseudonym only survives until something joins it to an identified record. Treating them as one category is the most common mistake — the interesting mitigation decisions usually sit on linkability, before identity is ever established. **Detectability versus disclosure.** Disclosure is about content. Detectability is about the *existence* of a record. Knowing that a person has a file in a patient register, an asylum caseload, or a whistleblower system can be the whole harm even if the file's contents remain encrypted. Candidates who collapse detectability into disclosure lose exactly the threats that encryption does not fix. **The two N's.** Non-repudiation and non-compliance are unrelated, and mixing them up is a giveaway. Non-repudiation is about a person being irrefutably bound to an action — a threat here, because for some flows the subject needs to be able to deny. Non-compliance is about the system's handling of data diverging from what it claims: retaining beyond a stated period, processing for a purpose it never declared, ignoring a stated consent state. **Unawareness is about the person, not the system.** It covers a subject oversharing because the interface never made the consequence visible, and a subject unable to see, correct, or stop what is held. It is the one type that sits on the human rather than on a component. ## What LINDDUN does not do The seven types are **categories of threat** — things that could go wrong. They are not vulnerabilities (the concrete flaw that permits the threat), not risks (the rated consequence), and not controls. LINDDUN itself carries no scoring model; you enumerate first and prioritise afterwards with whatever rating scheme the organisation already uses. A candidate who answers "LINDDUN tells you the severity" has confused enumeration with assessment. It is also not a legal checklist. The non-compliance type asks whether the system does what its own stated policy says; it does not tell you which lawful basis applies or what a data-subject request must contain. ## Naming versions Recent LINDDUN material uses gerunds and clearer labels — Linking, Identifying, Non-repudiation, Detecting, Data Disclosure, Unawareness & Unintervenability, Non-compliance. The count and the meanings are unchanged; the renaming mostly removes the awkward noun forms and makes explicit that unawareness includes the subject's inability to intervene. Either vocabulary is acceptable in an interview as long as you can list seven and say what property each one negates.

  • How does linkability differ from identifiability?
    Linkability means you can tell that two items concern the same subject without knowing who that subject is — two taps on the same card, two sessions with the same device fingerprint. Identifiability means you can attach the item to a specific person. Linkability is the precursor: build a large enough linked set and one joining record turns it into an identified profile. Mitigations usually have to land at the linkability stage, because once identity is established there is nothing left to protect.
  • Which LINDDUN type is the odd one out, and why?
    Unawareness. The other six describe properties of data or of system behaviour; unawareness describes the data subject's state — they share more than they realise, or cannot see and correct what is held about them. That is why it is analysed against the person in the model rather than against a store or a flow, and why its mitigations are about transparency and control rather than about protecting a component.
  • Does LINDDUN tell you how severe a privacy threat is?
    No. LINDDUN is an enumeration method: it produces a categorised list of what could go wrong. Rating and prioritisation are a separate step, done with whatever scheme the organisation already uses, weighing the impact on the individual rather than on the service. Candidates who claim the method scores threats have confused threat elicitation with risk assessment — the same distinction that separates naming a threat from rating a risk.

Think of a set of privacy promises — you can't be linked, named, pinned to an act, noticed, read, kept in the dark, or handled off-policy. LINDDUN is that list of promises written as the seven ways each one breaks.

saying these in an interview costs you the question

  • Says LINDDUN has six types, mirroring STRIDE
  • Merges linkability and identifiability into one idea
  • Treats detectability as a synonym for disclosure
  • Confuses non-repudiation with non-compliance
  • Calls unawareness a system logging problem
  • Claims LINDDUN outputs a severity score

context

open as a page

Why does a privacy threat model name the operator as an adversary, unlike a security model?

level: middleimportance: must knowfreq 62%

basics

~20 s

A security model protects the system from unauthorised parties. A privacy model protects the person the data describes, including from the operator's own authorised staff and vendors. So the fix is collecting and keeping less, not stronger access control.

open as a page

How do you run a one-hour rapid threat model on a feature that ships Friday?

level: middleimportance: must knowfreq 58%

basics

~20 s

Fix the scope to the change itself, sketch its flows and trust boundaries, walk one fixed question set over every boundary crossing, and leave with ranked threats that each have an owner. You buy the obvious high-impact threats and spend completeness.

open as a page

Which criteria actually decide which threat modeling method a team should use?

level: middleimportance: must knowfreq 62%

basics

~20 s

Fit decides it, not fashion: team maturity, the system's type and risk profile, any regulatory or contractual driver, the time budget per model, and who consumes the output. A lighter method run every release beats a heavier one nobody finishes.

open as a page

Why does a CAPEC-driven sweep of an airline loyalty-points API miss arbitrage between member accounts?

level: seniorimportance: must knowfreq 55%

basics

~20 s

Points arbitrage is a chain of legitimate operations permitted by that system's own rules, and no catalog holds rules it never saw. A library sets a floor of known patterns; novel abuse comes from an asset-driven pass.

open as a page

Why is a release security checklist a floor for threat modeling rather than a replacement?

level: juniorimportance: should knowfreq 46%

basics

~20 s

A checklist encodes threats already found on other systems, so it catches known misses cheaply and uniformly. It cannot see what is specific to your design: your business logic, your boundaries, your attacker. Put it beneath a model, not in place of one.

open as a page

How do you use CAPEC attack patterns and their CWE links during a design review?

level: middleimportance: should knowfreq 42%

basics

~20 s

CAPEC is a public catalog of attack patterns, and each pattern links to the CWE weaknesses that make it possible. In a design review you pull the patterns matching your entry points, then design against the linked weaknesses.

open as a page

In OCTAVE Allegro, what is the difference between an information asset and its containers?

level: middleimportance: should knowfreq 34%

basics

~20 s

The information asset is the data itself; its containers are the technical, physical and people places where that data is stored, transported or processed. OCTAVE Allegro profiles the asset once, then inherits risk from every container, including containers another organization operates.

open as a page

What are PASTA's seven stages in order, and what does each stage produce?

level: middleimportance: should knowfreq 46%

basics

~20 s

PASTA runs: define business objectives, define technical scope, decompose the application, threat analysis, weakness and vulnerability analysis, attack modeling, then risk and impact analysis. Each stage feeds the next, ending in business-priced risks plus countermeasures.

open as a page

In Trike, how does the actor-asset-action matrix turn stated requirements into a threat list?

level: middleimportance: should knowfreq 35%

basics

~20 s

Trike grids every actor against every asset, marking each create, read, update and delete cell allowed, disallowed, or conditional. Threats are the complement: an actor performing a disallowed action, or being denied an allowed one.

open as a page

In VAST threat modeling, what is the difference between an application model and an operational model?

level: middleimportance: should knowfreq 45%

basics

~20 s

VAST builds two model types. An application threat model uses a process-flow diagram that follows features and the calls between components the way a delivery team designs them. An operational threat model uses a data-flow diagram of the deployed shared infrastructure those applications run on.

open as a page

Why does LINDDUN treat non-repudiation as a privacy threat when security treats it as a goal?

level: seniorimportance: should knowfreq 46%

basics

~20 s

Non-repudiation destroys plausible deniability. Where a person must be able to deny acting, such as a whistleblower filing a report, evidence that irrefutably binds them to the act is itself the harm, so LINDDUN treats it as a threat.

open as a page

Running a per-element LINDDUN pass over a transit card tap ledger, which threats dominate and where?

level: seniorimportance: should knowfreq 52%

basics

~20 s

Linkability on the tap ledger dominates, escalating to identifiability. A per-element pass applies six LINDDUN types to the flow, store and analytics process, but only linkability, identifiability and unawareness to the rider, whose card number is a pseudonym, not anonymity.

open as a page

Why does PASTA begin with business objectives instead of the system design?

level: seniorimportance: should knowfreq 41%

basics

~20 s

Starting from business objectives gives PASTA a yardstick: the final stage rates each attack path by the damage it does to a stated objective. It also surfaces abuse of legitimate features, which a design-first pass misses because nothing is technically broken.

open as a page

How do you run STRIDE elicitation inside a PASTA-framed engagement without duplicate or orphan findings?

level: seniorimportance: should knowfreq 44%

basics

~20 s

Let PASTA's stages own scope and impact and let STRIDE own elicitation: the category walk populates the threat-analysis stage, and its output feeds attack modeling as input, not as a second list. One register, one granularity, one de-duplication pass.

open as a page

What kinds of threats does Trike's requirements-driven derivation systematically miss?

level: seniorimportance: should knowfreq 26%

basics

~20 s

Anything the requirements never named: actors nobody wrote down, assets outside the grid such as tokens, logs and backups, and threats that are not one actor acting on a business asset. A stated rule that is itself over-broad also passes silently.

open as a page

VAST is chosen to model 700 insurer applications in two quarters: what scales, and what depth is lost?

level: seniorimportance: should knowfreq 38%

basics

~20 s

What scales is production: a process-flow application model is drawn by the product team from how they already describe their features, so 700 models are made in parallel instead of queued behind a handful of facilitators. What is lost is per-model depth and attacker-motivation reasoning.

open as a page

What does OCTAVE Allegro add to a programme that already threat-models every design?

level: principalimportance: should knowfreq 29%

basics

~20 s

Design-level modeling analyses one system you drew; OCTAVE Allegro follows an information asset across every container that holds it, including paper, people and other organizations. It answers which assets deserve attention and judges impact against business-ranked criteria, so the two run at different cadences.

open as a page

Driving data collected for insurance pricing is now wanted by the claims team - how do you evaluate that reuse?

level: principalimportance: should knowfreq 38%

basics

~20 s

Treat it as a purpose-limitation threat, not an access request: nothing is breached, yet data a customer gave to be priced is used against them in a claim. Test compatibility, seek a less invasive form, enforce it technically.

open as a page

How does OCTAVE Allegro turn an area of concern into a documented threat scenario?

level: seniorimportance: nice to knowfreq 21%

basics

~20 s

An area of concern is a stakeholder's plain-language worry about an asset in one of its containers. OCTAVE Allegro expands each one into a threat scenario by filling in actor, means, motive, outcome and the violated security requirement, then sweeps threat trees for scenarios nobody voiced.

open as a page

A loyalty team wants to sell an 'anonymised' grocery basket dataset - what is the privacy threat?

level: seniorimportance: nice to knowfreq 30%

basics

~20 s

Stripping names and loyalty IDs gives pseudonymised data, not anonymised. Purchase histories are sparse and near-unique, so rare item combinations act as identifiers and a partner can re-link shoppers to other data. Aggregate, generalise, or release answers instead of rows.

open as a page

What does a Security Cards deck surface that a checklist-driven threat review misses?

level: seniorimportance: nice to knowfreq 28%

basics

~20 s

Security Cards is organised around human impact, adversary motivations, adversary resources and adversary methods, so it forces a team to name who would attack and why. Control-oriented lists never prompt that, and miss attackers whose goal is not money.

open as a page

Should a security programme mandate a CAPEC-derived attack-library sweep on every design review?

level: principalimportance: nice to knowfreq 26%

basics

~10 s

Mandate the outcome, not the traversal. A curated, architecture-specific library is a good floor for new teams, but percent-of-catalog coverage is theatre: require threats that came from the design too.

open as a page

When would you run LINDDUN GO instead of a full per-element LINDDUN pass, and what do you give up?

level: principalimportance: nice to knowfreq 27%

basics

~20 s

LINDDUN GO is the lightweight card-based form: a deck of prompting cards worked against a rough system sketch with non-specialists. It trades the full method's exhaustive per-element coverage and its defensible record for speed and reach.

open as a page

When is PASTA's full seven-stage run worth the cost, and how would you tailor it?

level: principalimportance: nice to knowfreq 27%

basics

~20 s

Run all seven stages where loss is large, trust is contested and the design is long-lived — the case that justifies weeks of cross-functional input. Elsewhere keep stage one and stage seven, reuse decomposition, and compress the middle into one evidence-informed pass.

open as a page

Would you mandate one threat modeling method across every team, or let each team choose?

level: principalimportance: nice to knowfreq 34%

basics

~20 s

Neither extreme. Set a house default matched to the median system, publish the selection criteria and two or three alternatives, and require a written rationale to deviate. Uniformity buys comparability; forced uniformity buys ritual compliance where it does not fit.

open as a page

Is Trike-style requirements modeling worth adopting when no written access rules exist?

level: principalimportance: nice to knowfreq 18%

basics

~20 s

Usually yes, but narrowly. The cost is not the analysis; it is authoring the authorization rules the organisation never wrote — and that written rule set, not the threat list, is the main payoff. Scope it to the authorization-dense core.

open as a page

A VAST rollout produced a model per system but expert review capacity did not grow - what now?

level: principalimportance: nice to knowfreq 25%

basics

~20 s

Say plainly that a model per system proves production capacity, not security. Stop trying to review every model, sample by exposure and asset value, review recurring threat classes rather than documents, and be explicit with the mandate owner about what modelled does and does not mean.

open as a page