Assumptions are part of the threat model
Every model rests on things taken for granted, and writing them down is what makes it reviewable later.
We assume the network is trusted. We assume this service authenticates callers. We assume the provider does X. Those assumptions are frequently the thing that changed when a model stops being valid, and if they were never recorded nobody notices they have been invalidated.
More on Threat modelling
- Assets are what attackers want to affectThey came for one thing
- Attack trees decompose goals into possible pathsEvery way up the same hill
- Abuse cases describe intentional misuseIt worked perfectly
- Threat models expire as systems changeThe plan stopped growing
- Mitigations should connect to specific threatsEvery thread ends on a peg
- Threat models include failure without an attackerTwo ways the same mast falls
