Threat modelling asks how a design can fail before code exists
The cheapest moment to find a design flaw is before anything has been built on top of it.
Once code exists, changing the shape of the system means rework across everything that depends on it, so the answer tends to be a compensating control instead. Doing it at design time costs an afternoon and occasionally removes an entire category of problem.
More on Secure development
- Input validation defines what the application acceptsOne shape fits
- Security requirements are product requirementsThey go on the same sheet
- Code review and automated scanning see different risksThe magnet and the eye
- Security tests should exercise abuse casesThe load nobody specified
- Feature flags can become security statesSomebody left it up
- Error handling should fail predictablyBreak the same way every time
