Define Threats, Attacks (align with CAPEC/MITRE) and Impact
https://capec.mitre.org/data/definitions/188.html
Example: https://attack.mitre.org/techniques/T1474/001/ (Supply Chain Compromise: Compromise Software Dependencies and Development Tools)
in MASWE-0041: Identifying vulnerable dependency versions in the app package and using public advisories or exploits.
Align impact labels to STRIDE: https://learn.microsoft.com/en-us/previous-versions/commerce-server/ee823878(v=cs.20)?redirectedfrom=MSDN
Define Threats, Attacks (align with CAPEC/MITRE) and Impact
https://capec.mitre.org/data/definitions/188.html
Example: https://attack.mitre.org/techniques/T1474/001/ (Supply Chain Compromise: Compromise Software Dependencies and Development Tools)
in MASWE-0041: Identifying vulnerable dependency versions in the app package and using public advisories or exploits.
Align impact labels to STRIDE: https://learn.microsoft.com/en-us/previous-versions/commerce-server/ee823878(v=cs.20)?redirectedfrom=MSDN