Riskio Card Decks
This page explains the Threat, Defence, and Information cards used during Riskio gameplay and how they support learning.
Attack Deck: The attack deck is formed by six suits of 13 cards (the same as a typical card deck: Ace, 2 to 10, then Jack, Queen and King). Each suit of the attack deck was based on categorising the attacks based on the six Microsoft STRIDE threat categories: Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, and Elevation of Privilege.
Defence Deck: The defence deck is formed by a single suit of 13 cards: 2 to 10, then Jack, Queen, King and Ace, representing the core security controls that can be directly applied to mitigate against known attack types.
Information Deck: The information deck is formed by a single suit of 13 cards: 2 to 10, then Jack, Queen, King and Ace, representing security-related events resulting in a successful cyber attack unless the correct defence card is played. The games master uses this deck to test players' defence strategies and help the gameplay.
Click on the back of the card to see the complete suit of cards.
Spoofing Suit
Attacks to procedures can maliciously impersonate users but can also spoof websites or servers.
Tampering Suit
Attacks that alter data at rest, e.g. by exploiting a vulnerability in application front-ends or transit, e.g. due to a lack of message encryption.
Repudiation Suit
Threats to claim to have not performed an action.
Information Disclosure Suit
Threats to the confidentiality of information.
Denial of Service Suit
Availability of services to users.
Elevation of Privilege Suit
Threats against the authorisation controls.
Defence Suit
Defence cards describe a pattern of behaviour that protects the player against an exploitation attempt.
Information Suit
Games master can use Scaffolding by framing, guiding and supporting using the information deck of cards.