To get started with STRIDE, one can think about all the element or all the interaction between components.
STRIDE-per-element is good for beginners, but STRIDE-per-interaction makes it easier to understand threats.
STRIDE-per-Element
Different threats affect each type of element:
- External Entity
- Process
- Data Store
- Dataflow
STRIDE-per-Interaction
Focus shift from individual elements to the interactions between elements, then concentrate on where those components “meet”.