Security Engineering Risk Analysis (SERA) Threat Archetypes

SEI Report
This report examines the concept of threat archetypes and how analysts can use them during scenario development.
Publisher

Software Engineering Institute

Abstract

Over the past five years, we at the SEI used the SERA Method to conduct multiple SoS cyber-risk analyses for DoD and federal system acquisition programs. Based on our pilot experiences, we identified the development of cyber-risk scenarios as the key to a successful assessment. At the same time, we observed that scenario development can be a time-consuming and difficult task since analysts must have sufficient knowledge, skills, and abilities to develop and evaluate cyber-risk scenarios. When analysts do not understand the ways in which software, hardware, and firm-ware can be compromised, important scenarios can be poorly constructed or even overlooked.

An overarching goal of our research is to teach others to apply the SERA Method. To facilitate the transition of the SERA Method to adopters throughout the cybersecurity community, we explored more systematic ways of developing scenarios. As a result, we chartered a research task to explore the concept of using patterns of threats, called threat archetypes, to facilitate the process of scenario development.

Cite This SEI Report

Alberts, C., & Woody, D. (2020, December 16). Security Engineering Risk Analysis (SERA) Threat Archetypes. Retrieved September 17, 2026, from https://www.sei.cmu.edu/library/security-engineering-risk-analysis-sera-threat-archetypes/.

@techreport{alberts_2020,
author={Alberts, Christopher and Woody, Dr. Carol},
title={Security Engineering Risk Analysis (SERA) Threat Archetypes},
month={Dec},
year={2020},
institution={Software Engineering Institute, Carnegie Mellon University},
url={https://www.sei.cmu.edu/library/security-engineering-risk-analysis-sera-threat-archetypes/},
note={Accessed: 2026-Sep-17}
}

Alberts, Christopher, and Dr. Carol Woody. "Security Engineering Risk Analysis (SERA) Threat Archetypes." Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, December 16, 2020. https://www.sei.cmu.edu/library/security-engineering-risk-analysis-sera-threat-archetypes/.

C. Alberts, and D. Woody, "Security Engineering Risk Analysis (SERA) Threat Archetypes," Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, 16-Dec-2020 [Online]. Available: https://www.sei.cmu.edu/library/security-engineering-risk-analysis-sera-threat-archetypes/. [Accessed: 17-Sep-2026].

Alberts, Christopher, and Dr. Carol Woody. "Security Engineering Risk Analysis (SERA) Threat Archetypes." Software Engineering Institute, Carnegie Mellon University, Software Engineering Institute, 16 Dec. 2020. https://www.sei.cmu.edu/library/security-engineering-risk-analysis-sera-threat-archetypes/. Accessed 17 Sep. 2026.

Alberts, Christopher; & Woody, Dr. Carol. Security Engineering Risk Analysis (SERA) Threat Archetypes. Software Engineering Institute. 2020. https://www.sei.cmu.edu/library/security-engineering-risk-analysis-sera-threat-archetypes/