isms-threat-modeling-adaptation.md

April 18, 2026 ยท View on GitHub

Hack23 Logo

๐ŸŽญ ISMS Threat Modeling โ†’ Political Threat Adaptation

๐Ÿ“Š Mapping STRIDE & ATT&CK to Democratic Process Threat Analysis
๐ŸŽฏ STRIDE ยท MITRE ATT&CK ยท Attack Trees ยท Threat Agents โ†’ Political Threats

Owner Version Effective Date Classification

๐Ÿ“‹ Document Owner: CEO | ๐Ÿ“„ Version: 1.0 | ๐Ÿ“… Last Updated: 2026-03-26 (UTC)
๐Ÿ”„ Review Cycle: Quarterly | โฐ Next Review: 2026-06-26
๐Ÿข Owner: Hack23 AB (Org.nr 5595347807) | ๐Ÿท๏ธ Classification: Public


โš ๏ธ HISTORICAL REFERENCE ONLY: This document records the original adaptation from ISMS frameworks. The active methodology has moved to the Political Threat Taxonomy (v3.0) which replaces STRIDE categories with politically-native threat categories. See political-threat-framework.md for the current framework.

๐ŸŽฏ Purpose

This reference document maps Hack23 ISMS Threat_Modeling.md frameworks โ€” STRIDE, MITRE ATT&CK, Attack Trees, and Threat Agents โ€” to Riksdagsmonitor's political threat analysis methodology. The adaptation enables systematic, framework-consistent political threat analysis using the same analytical rigour applied to cybersecurity threats.


๐ŸŽญ STRIDE Categories โ†’ Political Threats

The ISMS implements STRIDE as a per-element threat categorisation for IT systems. The political adaptation applies STRIDE to the democratic process as the "system" being threatened:

STRIDE CategoryCybersecurity ThreatPolitical ThreatPolitical Example
S โ€” SpoofingAttacker impersonates legitimate user/system๐ŸŽญ DisinformationFalse attribution of policy positions; fabricated quotes; misrepresented voting records
T โ€” TamperingAttacker modifies data or code๐Ÿ“ Policy CorruptionUndisclosed lobbying alters legislation text; regulatory capture distorts implementation
R โ€” RepudiationActor denies performing action๐Ÿšซ Accountability EvasionPolitician contradicts their Riksdag voting record; government denies prior commitment
I โ€” Information DisclosureUnauthorised data exposure๐Ÿ”‡ Transparency FailureGovernment suppresses SOU findings; classification of politically inconvenient information
D โ€” Denial of ServiceService made unavailableโ›” Democratic ObstructionFilibustering; quorum obstruction; committee paralysis; budget stonewalling
E โ€” Elevation of PrivilegeUnauthorised access to higher permissions๐Ÿ‘‘ Power ConcentrationGovernment bypasses Riksdag via decree; minister exceeds legal authority; coalition partner demands policy veto

Adaptation Rationale

The STRIDE framework was designed for computer systems where each element has defined trust boundaries. In the political context:

  • The democratic system is the "asset" being protected
  • Constitutional norms are the equivalent of "access controls"
  • Parliamentary procedure is the equivalent of "protocol"
  • KU granskning is the equivalent of "audit logging and review"

The key insight: just as STRIDE identifies ways actors bypass security controls, political STRIDE identifies ways actors bypass democratic accountability controls.


๐ŸŽ–๏ธ MITRE ATT&CK โ†’ Political Actor Tactics

The ISMS maps MITRE ATT&CK techniques to cybersecurity attack patterns. The political adaptation maps ATT&CK tactics to political actor behaviour patterns:

ATT&CK TacticCybersecurity MeaningPolitical Actor TacticObservable Signal
Initial AccessGain first footholdCoalition entry negotiationCooperation agreement signed
ExecutionRun malicious codeLegislation enactedRiksdag vote passes
PersistenceMaintain footholdCoalition maintenanceRepeated budget agreement renewals
Privilege EscalationGain higher accessGovernment power expansionMinisterial decree usage rate
Defense EvasionAvoid detectionAccountability evasionKU investigation delays; classified documents
CollectionGather informationOpposition intelligence gatheringInterpellationer volume + topic analysis
Command and ControlMaintain attack infrastructureParty discipline enforcementWhipping patterns in voteringar
ExfiltrationRemove data from targetPolicy reversalGovernment abandons campaign commitment
ImpactDisrupt/destroyDemocratic disruptionCoalition collapse, constitutional crisis

๐ŸŒณ Attack Trees โ†’ Democratic Process Threat Trees

The ISMS uses attack trees to model how goals are achieved through combinations of actions. Political attack trees model how democratic process goals can be undermined:

Attack Tree: Coalition Destabilisation

graph TD
    Root["๐Ÿ”ด GOAL: Collapse Governing Coalition"]
    
    Root --> A["Direct: No-confidence vote passes"]
    Root --> B["Indirect: Key coalition partner exits"]
    Root --> C["Structural: Budget vote fails"]
    
    A --> A1["Recruit defectors from coalition"]
    A --> A2["Combine opposition blocs"]
    A --> A3["National crisis erodes support"]
    
    B --> B1["SD withdraws support agreement"]
    B --> B2["L or KD internal vote to leave"]
    B --> B3["M leadership crisis"]
    
    C --> C1["Opposition wins budget amendment"]
    C --> C2["Coalition partner abstains on key line"]
    C --> C3["Minority government budget rejected"]
    
    style Root fill:#FFEBEE
    style A fill:#FFF3E0
    style B fill:#FFF3E0
    style C fill:#FFF3E0

Attack Tree: Transparency Suppression

graph TD
    Root2["๐Ÿ”ด GOAL: Suppress Politically Inconvenient Information"]
    
    Root2 --> D["Classify document"]
    Root2 --> E["Delay SOU publication"]
    Root2 --> F["Limit remiss distribution"]
    Root2 --> G["Control media narrative"]
    
    D --> D1["Invoke national security"]
    D --> D2["Personal data claim"]
    
    E --> E1["Commission narrow terms of reference"]
    E --> E2["Extend inquiry timeline"]
    
    G --> G1["Selective briefing of friendly media"]
    G --> G2["Off-record contradictory statement"]
    
    style Root2 fill:#fce4ec

๐Ÿ‘ฅ Threat Agents โ†’ Political Actors

The ISMS classifies threat agents by motivation and capability. The political adaptation classifies political actors using the same framework:

ISMS Threat Agent TypeISMS CharacteristicsPolitical ActorPolitical Characteristics
External attackerHigh motivation, external to org, variable capabilityForeign state actorHigh motivation (destabilisation), external to Sweden, high capability (Russia, China)
Insider threatInternal access, variable motivationCoalition partner acting against coalition interestInternal access to government, variable motivation (policy vs. power)
Script kiddieLow capability, opportunisticFringe political actorLow influence, opportunistic media disruption
Nation-stateHigh capability, strategic motivationEU Commission / NATOHigh institutional capability, treaty-based motivation
Organised crimeFinancial motivation, sophisticatedLobby/industry captureFinancial motivation, sophisticated policy access
CompetitorBusiness motivation, targetedOpposition partyElectoral motivation, targeted coalition exploitation


Document Control:

  • Path: /analysis/reference/isms-threat-modeling-adaptation.md
  • Source ISMS Doc: Threat_Modeling.md
  • Classification: Public
  • Next Review: 2026-06-26