Threat Model
STRIDE Analysis
| Threat | Mitigation |
|---|---|
| Spoofing | JWT authentication, mTLS between services |
| Tampering | TLS in transit, DB encryption at rest |
| Repudiation | Audit logging with correlation IDs |
| Information Disclosure | RBAC, PII masking in logs |
| Denial of Service | Rate limiting, HPA, circuit breakers |
| Elevation of Privilege | RBAC, least privilege IAM |