LINDDUN
Privacy threat modeling framework that decomposes privacy threats into seven categories, the privacy counterpart to STRIDE.
Definition
LINDDUN is a privacy-focused threat modeling methodology developed at KU Leuven. The acronym names seven privacy threat categories: Linkability, Identifiability, Non-repudiation, Detectability, Disclosure of information, Unawareness, and Non-compliance. LINDDUN GO (a lightweight card-deck variant) and LINDDUN PRO (a full data-flow-diagram methodology) walk teams through identifying privacy threats in each category against data flows and stores. Output is a prioritized set of privacy threats with mappings to privacy-enhancing technologies (PETs) and controls.What this means in practice
For medical devices that process PHI or generate identifiable health data, and especially for cloud-connected SaMD, AI/ML devices that retain inference logs, and digital therapeutics, LINDDUN complements STRIDE by surfacing threats STRIDE doesn't cover (re-identification of pseudonymized data, inference of sensitive attributes, linkability across datasets). EU GDPR and HIPAA both expect privacy-by-design analysis; LINDDUN is the most rigorous public methodology for it.- •Running STRIDE only and assuming privacy is covered, STRIDE addresses security; LINDDUN addresses privacy, and they identify different threats.
- •Skipping the PET (privacy-enhancing technology) mapping, without it, LINDDUN produces threats with no controls.
- •Limiting LINDDUN to the data layer, privacy threats also arise from UI design (Unawareness) and process design (Non-compliance).
Related terms
Grouped by themeEditor's picks
· Hand-selected related conceptsThe HIPAA-defined process of removing identifiers from PHI so the resulting data is no longer subject to the Privacy Rule.
U.S. federal law governing the privacy and security of protected health information.
Individually identifiable health information (PHI) and its electronic form (ePHI) - the data class HIPAA protects.
The bundle of cybersecurity artifacts a sponsor includes in a 510(k), De Novo, PMA, or HDE submission for a cyber device.
More in Cybersecurity
· Same categoryA six-category framework for enumerating threats: Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege.
A structured analysis that identifies how an attacker could compromise a medical device and what controls mitigate each threat.
AAMI/ANSI standard establishing requirements for medical-device cybersecurity activities throughout the lifecycle.
AAMI Technical Information Report providing MedTech-specific guidance on cybersecurity risk management.
Primary references
3 sources- 1
LINDDUN privacy threat modelingVerifiedKU Leuvenlinddun.org
- 2
ENISA Privacy and Data Protection by DesignVerifiedENISAenisa.europa.eu
- 3
HSCC - Health Sector Coordinating CouncilVerifiedHSCChealthsectorcouncil.org
Inline markers like [1] jump to the matching reference above.