Threat models expire as systems change
A threat model describes a system at a point in time, and systems move.
New integrations, new data, a supplier replaced, a component reused for something it was not designed for. The model is not wrong so much as out of date, and an out-of-date model is worse than none because it is consulted with confidence. Tying review to significant change works better than tying it to a calendar.
More on Threat modelling
- Assets are what attackers want to affectThey came for one thing
- Attack trees decompose goals into possible pathsEvery way up the same hill
- Abuse cases describe intentional misuseIt worked perfectly
- Mitigations should connect to specific threatsEvery thread ends on a peg
- Threat models include failure without an attackerTwo ways the same mast falls
- Data-flow diagrams reveal hidden crossingsDraw the pipes, find the crossings
