A Threat Analysis Model for Identity and Access Management

Nadia Jemil Abdu, Ulrike Lechner


Cyber attacks as a threat to business and national security have become concerns to organizations and governments. Potential impacts of attacks are financial loss, fraud, reputation damage, and legal costs. Identification of security threats is part of securing information systems as it involves identifying threats and challenges which need to be addressed by implementing appropriate countermeasures and realistic security requirements. Our study focuses on threat analysis and modeling for digital identities and identity management within and across complex and networked systems. Further, a preliminary version of a reference threat analysis model that supports threat analysis for identity management is proposed and discussed in this paper.


