threatmodelingmanifesto.org - Threat Modeling Manifesto

Description: The Threat Modeling Manifesto documents the values, principles and key characteristics as an industry guidance for conducting threat modeling.

Example domain paragraphs

Threat modeling is analyzing representations of a system to highlight concerns about security and privacy characteristics.

At the highest levels, when we threat model, we ask four key questions :

When you perform threat modeling, you begin to recognize what can go wrong in a system. It also allows you to pinpoint design and implementation issues that require mitigation, whether it is early in or throughout the lifetime of the system. The output of the threat model, which are known as threats, informs decisions that you might make in subsequent design, development, testing, and post-deployment phases.

Links to threatmodelingmanifesto.org (10)