LOGBOOK

HELP

1 / 28
Other keys: showSpace: good1-4: rate0: skip5: flag

Question

Who should be involved in a threat modeling analysis session and who takes ownership?

Answer

The technical project manager owns and schedules it; the architect, developer, and tester must attend.

The technical project manager takes ownership and schedules the session because they control the timeline and can compel the right people to show up.

Required participants:

  • Architect
  • Developer
  • Tester

Each threat should be discussed by the team. Some threats will have little impact and can be noted, while others need to be mitigated.

Why this matters: Different perspectives catch different threats - developers see implementation issues, testers think about edge cases, architects understand system-wide implications.

or press any other key

Question

What is the purpose of mitigation in threat modeling?

Answer

To actually address or lessen each threat you found — so the software resists attack and users stay protected.

Mitigation means to address or lessen a problem.

The goals of mitigation are:

  1. Protect users from security threats
  2. Design secure software that resists attacks

Key insight: Mitigation is the whole point of threat modeling - without addressing the threats you find, the exercise is pointless.

or press any other key