Threat modelling is a decision tool, not a ceremony
The output that matters is a decision, not a document.
A session that produces a diagram, a report and no change to the design has consumed a day. One that results in an extra check, a removed feature or an accepted risk has done its job. If the architecture is finished before the session happens, it is a review, and it should be described as one.
More on Threat modelling
- Assets are what attackers want to affectThey came for one thing
- Attack trees decompose goals into possible pathsEvery way up the same hill
- Abuse cases describe intentional misuseIt worked perfectly
- Threat models expire as systems changeThe plan stopped growing
- Mitigations should connect to specific threatsEvery thread ends on a peg
- Threat models include failure without an attackerTwo ways the same mast falls
