Tema: threat-modelling
-
Threat modelling a feature with STRIDE in one working session
Draw the feature as a data-flow diagram with trust boundaries, walk every element through the six STRIDE categories, decide per threat whether to mitigate, eliminate, transfer or accept, and write the outcome down as testable requirements; the Threat Modeling Manifesto's four questions are the agenda.
-
Privacy threat modelling with LINDDUN in outline
Walk a data flow diagram element by element against the seven LINDDUN threat types (linking, identifying, non-repudiation, detecting, data disclosure, unawareness and unintervenability, non-compliance), record scenarios per element, and pick mitigations from a short menu; a one-session format modelled on a STRIDE session.
Legible por máquina: JSON