skip to content

PASTA's Seven Stages

PASTA runs seven stages from business objectives through decomposition, threat and weakness analysis, attack modeling to risk and impact. Interviewers ask what makes it risk-centric and what it costs.

on this pageshow

questions

3

What are PASTA's seven stages in order, and what does each stage produce?

level: middleimportance: should knowfreq 46%

answer

  1. seven stages, business before diagram
  2. objectives, then scope, then decompose
  3. evidence-driven threat step sits fourth
  4. weaknesses before attack paths
  5. ends in countermeasures and residual risk

basics

~20 s

PASTA runs: define business objectives, define technical scope, decompose the application, threat analysis, weakness and vulnerability analysis, attack modeling, then risk and impact analysis. Each stage feeds the next, ending in business-priced risks plus countermeasures.

solid answer

~50 s

PASTA (Process for Attack Simulation and Threat Analysis) is a seven-stage process, and the order is the method. Stage 1 defines business objectives, compliance obligations and business impact. Stage 2 defines the technical scope — the services, dependencies and infrastructure that support those objectives. Stage 3 decomposes the application into actors, assets, entry points, data flows and trust boundaries. Stage 4 is threat analysis: which adversaries realistically operate against this kind of system, grounded in incident and fraud evidence. Stage 5 correlates those threats to actual weaknesses in the decomposed components. Stage 6 models attacks — surfaces and attack trees showing how weaknesses chain toward the assets. Stage 7 rates the surviving paths against the stage-1 impact, picks countermeasures and states residual risk. Every stage consumes the previous stage's artifact, so skipping one leaves the next unsupported.

go deeper

for a junior

Be able to say that PASTA is a seven-stage, risk-centric threat modeling process that starts from business objectives, and name the stages in order without inventing extra ones.

for a middle

Explain what each stage consumes and produces, and why decomposition sits at stage three rather than stage one. Interviewers listen for the handoff between weakness analysis and attack modeling.

for a senior

Show you have run something like it: which stages produced real value on a system you worked on, where the evidence for stage four came from, and what the stage-seven output changed in the plan.

for a principal

Own the cost question. Seven stages need product, finance and operations input, so be ready to say which systems justify a full run and how you would keep the stage-one-to-stage-seven traceability if you compress the middle.

## What PASTA is PASTA — Process for Attack Simulation and Threat Analysis — is a **risk-centric, seven-stage threat modeling methodology**. It is not a mnemonic or a category list; it is a *process*. A mnemonic-driven method points at a diagram element and asks what could go wrong with it. PASTA starts outside the diagram, with what the business is trying to achieve, and ends with a set of viable attack paths priced against that objective and matched to countermeasures. ## The seven stages, with their inputs and outputs **1. Define Objectives.** Business objectives, regulatory and compliance obligations, and a business impact analysis. Output: a statement of what the system exists to do and what it costs the organisation when that stops being true. This is the yardstick every later stage is measured against. **2. Define Technical Scope.** The technology footprint supporting those objectives: services, third-party APIs, data stores, infrastructure, libraries, operational tooling. Output: an explicit in-scope boundary. Stage 2 answers *what is in the picture*, not yet *how it works*. **3. Application Decomposition.** Use cases, actors, assets, entry points, privilege levels, data flows and trust boundaries. Output: a per-component understanding of how the system actually behaves. This is the stage that most resembles conventional diagram-first modeling — and note that it sits third, not first. **4. Threat Analysis.** Which adversaries plausibly act against this class of system, drawn from incident history, fraud reporting, abuse logs and industry threat intelligence. Output: an evidence-grounded, scoped threat list rather than an imagined one. **5. Weakness and Vulnerability Analysis.** Correlate those threats to real weaknesses in the components mapped at stage 3 — design flaws, known weakness classes, and existing findings from testing. Output: which weaknesses the identified threats could actually reach and use. **6. Attack Modeling and Simulation.** Enumerate the attack surface and build attack trees showing how an adversary chains the stage-5 weaknesses toward the stage-1 assets, then test those paths against the design. Output: viable attack *paths*, not a bag of isolated defects. **7. Risk and Impact Analysis.** Qualify or quantify the business risk of each viable path against the stage-1 impact analysis, select countermeasures, and state the residual risk that remains after them. Output: a prioritised, business-anchored risk picture with decisions attached. ## Why the order carries the weight Each stage consumes the previous stage's artifact. Stage 5 cannot honestly say which weaknesses matter without stage 3's component map; stage 6 cannot build a path without stage 5's weaknesses; stage 7 cannot price anything without stage 1's impact analysis. The chain also runs backwards as traceability: for any countermeasure you propose, you can point to the attack path, the weakness, the threat and finally the business objective it protects. That backwards walk is what makes PASTA's output defensible to people who do not care about diagrams. ## A worked thread: a prepaid airtime and utility top-up reseller platform **Stage 1.** The objective is to sell top-ups through independent reseller agents against a prefunded float account, on thin margin and high volume; the impact statement is float loss and margin erosion. **Stage 2.** Technical scope pulls in four telco vending APIs, the float ledger, the agent-facing app, and the nightly reconciliation job. **Stage 3.** Decomposition exposes the sequence: agent requests a vend, the float is debited, the telco call is made, and outcome reconciliation happens asynchronously. **Stage 4.** Threat analysis on this class of platform surfaces the agent-as-insider: a legitimate, authenticated reseller abusing ambiguous transaction outcomes rather than an outsider breaking in. **Stage 5.** Weakness analysis lands on the reconciliation window — a timed-out vend can be credited back while the telco actually delivered the airtime. **Stage 6.** Attack modeling turns that into a path: deliberately induce timeouts, collect reversals on delivered vends, keep the per-agent rate under any alerting threshold, and spread it across agent accounts. **Stage 7.** The risk is expressed as expected float loss per period against a thin margin, and countermeasures are chosen accordingly — synchronous outcome confirmation, holding reversals until the telco settles, per-agent velocity limits — with residual risk stated for what remains. ## Common confusions - **Stage 2 versus stage 3.** Scope is not decomposition. Stage 2 draws the fence; stage 3 explains the mechanics inside it. - **Stage 5 versus stage 6.** A weakness is a static property of a component; an attack is a path that chains weaknesses toward an asset. Many teams stop at stage 5 and hand over a defect list, which is exactly what PASTA is trying to improve on. - **PASTA is not a taxonomy.** There are no categories to enumerate per element; the elicitation comes from evidence at stage 4 and from path construction at stage 6. - **It is expensive.** Seven stages need input from product, finance and operations, not just security. That cost is the main reason teams tailor it.

  • What actually separates PASTA's stage five from stage six?
    Stage five, weakness and vulnerability analysis, asks which flaws exist in the components you decomposed — design weaknesses, known weakness classes, outstanding test findings. Stage six, attack modeling and simulation, asks how an adversary chains those flaws into a route that reaches an asset, usually expressed as attack surfaces and attack trees. A weakness with no reachable path is deprioritised at stage six; two individually minor weaknesses that compose into a full path get promoted. Stopping at stage five produces a defect list, not a threat model.
  • Which stage consumes external threat intelligence, and what does it do with it?
    Stage four, threat analysis. It pulls incident history, abuse and fraud reporting, production logs and industry reporting about this class of system, and uses them to scope which adversaries and behaviours are realistic here. The point is to constrain elicitation with evidence rather than brainstorming, so stage five correlates weaknesses against threats someone has actually observed. It also biases the model toward the attacker positions that matter for the system — an authenticated insider, a partner, a scaled fraud ring.
  • How does PASTA differ from a diagram-first, per-element elicitation method?
    A per-element method starts at stage three's artifact and enumerates categories against each element, which is fast and repeatable but treats every element as equally worth defending. PASTA puts business objectives and impact first, and rates at the end against them, so its output is ordered by what the loss is worth rather than by how many findings an element attracts. The cost is that PASTA needs business and threat-intelligence inputs a security team cannot produce alone, and it takes far longer per system.

It reads like an accident investigation run forwards: establish what the operation was supposed to achieve, map the machinery, then trace how a specific chain of failures reaches the thing you cared about.

saying these in an interview costs you the question

  • Says PASTA begins by drawing the data-flow diagram
  • Puts attack modeling before weakness analysis
  • Describes PASTA as a threat category mnemonic
  • Treats stage seven as producing a number with no countermeasures
  • Cannot say what any stage consumes from the previous one
  • Confuses defining technical scope with decomposing the application

context

open as a page

Why does PASTA begin with business objectives instead of the system design?

level: seniorimportance: should knowfreq 41%

basics

~20 s

Starting from business objectives gives PASTA a yardstick: the final stage rates each attack path by the damage it does to a stated objective. It also surfaces abuse of legitimate features, which a design-first pass misses because nothing is technically broken.

open as a page

When is PASTA's full seven-stage run worth the cost, and how would you tailor it?

level: principalimportance: nice to knowfreq 27%

basics

~20 s

Run all seven stages where loss is large, trust is contested and the design is long-lived — the case that justifies weeks of cross-functional input. Elsewhere keep stage one and stage seven, reuse decomposition, and compress the middle into one evidence-informed pass.

open as a page