Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Examples of Identified Threats, Risk Ratings, and Mitigations? #36

Open
levinebw opened this issue Oct 13, 2021 · 1 comment
Open

Examples of Identified Threats, Risk Ratings, and Mitigations? #36

levinebw opened this issue Oct 13, 2021 · 1 comment

Comments

@levinebw
Copy link

These are really useful assets for demonstrating how to diagraming the system, "What are we working on".

I don't see any artifacts that capture the threats that have been identified by these models (steps 2 and 3 of a a threat model). i.e., What can go wrong? What can we do about it?

Have I overlooked something, or is there a plan to add examples of a completed threat model exercise?

@zbraiterman
Copy link
Collaborator

Thank you, @levinebw, for bringing up these great points. I think that part of the intention of the attack tree submissions is to address step 2 (“What can go wrong?”).

We also, of course, welcome any suggestions you may have on how to incorporate contributions that address step 3 (“What can we do about it?”), as well as any other suggestions you may have, as we continue to build upon the Threat Modeling Cookbook.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants