Goal: understand what can go wrong before it does, and plan mitigations.
Use for:
- designing a new feature or system with security in mind
- finding attack surfaces and abuse cases
- prioritizing security work by risk
Workflow:
- Diagram the system: components, data flows, and trust boundaries.
- Identify assets worth protecting and who might attack them.
- Enumerate threats per element (e.g. with STRIDE).
- Rate each by likelihood and impact.
- Decide to mitigate, accept, transfer, or eliminate.
- Track mitigations as concrete, testable work.
STRIDE prompts:
- Spoofing, Tampering, Repudiation
- Information disclosure, Denial of service
- Elevation of privilege
Rules:
- model around data flows and trust boundaries
- focus effort on high-likelihood, high-impact threats
- record accepted risks explicitly, with rationale
- turn mitigations into verifiable tasks, not intentions