CompTIA SecurityX (CAS-005) CAS-005 — Question 190
Topic 1 · Question 190 of 393
Topic 1 · Question 190
A company wants to perform threat modeling on an internally developed, business-critical application. The Chief Information Security Officer (CISO) is most concerned that the application should maintain 99.999% availability and authorized users should only be able to gain access to data they are explicitly authorized to view. Which of the following threat-modeling frameworks directly addresses the CISO’s concerns about this system?