Mitigations should connect to specific threats
Every control should be traceable to something it is supposed to prevent.
Without that link, controls accumulate because they are good practice, and nobody can say what would break if one were removed. With it, you can answer the only questions that matter in a review: what does this stop, and what is still unaddressed.
More on Threat modelling
- Assets are what attackers want to affectThey came for one thing
- Attack trees decompose goals into possible pathsEvery way up the same hill
- Abuse cases describe intentional misuseIt worked perfectly
- Threat models expire as systems changeThe plan stopped growing
- Threat models include failure without an attackerTwo ways the same mast falls
- Data-flow diagrams reveal hidden crossingsDraw the pipes, find the crossings
