Data-flow diagrams reveal hidden crossings
Drawing where data actually goes exposes boundaries nobody knew were being crossed.
The exercise routinely finds a path through a third party, an export nobody documented, or a service talking to something it should not. That is most of the value: not the diagram itself, but the arguments it starts about arrows people disagree with.
More on Threat modelling
- Assets are what attackers want to affectThey came for one thing
- Attack trees decompose goals into possible pathsEvery way up the same hill
- Abuse cases describe intentional misuseIt worked perfectly
- Threat models expire as systems changeThe plan stopped growing
- Mitigations should connect to specific threatsEvery thread ends on a peg
- Threat models include failure without an attackerTwo ways the same mast falls
