Threat models expire as systems change

A threat model describes a system at a point in time, and systems move.

New integrations, new data, a supplier replaced, a component reused for something it was not designed for. The model is not wrong so much as out of date, and an out-of-date model is worse than none because it is consulted with confidence. Tying review to significant change works better than tying it to a calendar.

More on Threat modelling