Threat models include failure without an attacker
Not every threat has a person behind it.
A dependency going away, a certificate expiring, a supplier failing, a component behaving unexpectedly under load. These produce the same outcomes as an attack and are considerably more likely. Threat models that only consider adversaries miss the majority of things that will actually go wrong.
More on Threat modelling
- Assets are what attackers want to affectThey came for one thing
- Attack trees decompose goals into possible pathsEvery way up the same hill
- Abuse cases describe intentional misuseIt worked perfectly
- Threat models expire as systems changeThe plan stopped growing
- Mitigations should connect to specific threatsEvery thread ends on a peg
- Data-flow diagrams reveal hidden crossingsDraw the pipes, find the crossings
