skip to content

What are the Threat Modeling Manifesto's five value pairs, and what does valuing one side over the other commit you to?

level: middleimportance: should knowfreq 48%

answer

  1. Borrowed shape from another famous manifesto
  2. Five pairs, not four
  3. Checkbox compliance is one losing side
  4. Doing beats talking; refinement beats one delivery
  5. Right-hand items are lesser goods, not banned

basics

~20 s

The Threat Modeling Manifesto values finding and fixing design issues over checkbox compliance, people over process and tools, understanding as a journey over a snapshot, doing over talking, and continuous refinement over one delivery. Right-hand items are lesser goods, not worthless.

solid answer

~40 s

The Manifesto states five pairs: a culture of finding and fixing design issues over checkbox compliance; people and collaboration over processes, methodologies and tools; a journey of understanding over a security or privacy snapshot; doing threat modeling over talking about it; and continuous refinement over a single delivery. The `over` is borrowed from the Agile Manifesto's form and carries the same meaning: the right-hand item still has value, it just loses when you cannot have both. So compliance evidence, a named methodology and a written model are all fine — the Manifesto only tells you which one you sacrifice under pressure. Used honestly the pairs are a diagnostic, not a creed: when a practice degrades, you can usually point at the pair it inverted and predict what happens next.

go deeper

for a junior

Know that the document exists, that it takes the form of X over Y pairs, and be able to name two or three of them. Do not claim it mandates a specific method.

for a middle

Be ready to state all five pairs and explain what the word over means — the right-hand item is the lesser good, not a prohibition. Expect to be asked for an example of a pair being inverted.

for a senior

An interviewer expects you to use the pairs diagnostically on a real practice: point at the pair a struggling programme inverted and predict the consequence, rather than reciting the list.

for a principal

Own the tension the pairs create with the reporting your organisation needs. You will be asked how you keep evidence and measurement without letting process quietly become the practice, and the answer has to survive an auditor.

### Where the document comes from The Threat Modeling Manifesto is a short, freely published statement written in 2020 by a group of threat modeling practitioners who wanted to describe what good threat modeling looks like *without* crowning a single methodology. Its structure is openly borrowed from the Agile Manifesto: a set of `X over Y` value pairs, a handful of principles, then patterns that benefit the practice and anti-patterns that hinder it. That form matters more than it looks. A value pair is not a rule, not a control and not a maturity level. It is a **tie-breaker** for the arguments that actually happen when a practice is under schedule pressure and two good things are competing. ### The five value pairs 1. **A culture of finding and fixing design issues over checkbox compliance.** The point of the exercise is that a design changes. A programme that produces a signed artifact per release and no design changes has satisfied the right-hand item and abandoned the left. 2. **People and collaboration over processes, methodologies, and tools.** Threats are found by people who understand the system talking to each other. Process and tooling carry that conversation; they do not replace it. 3. **A journey of understanding over a security or privacy snapshot.** The model is a shared, growing understanding of the system, not a photograph of it on one date. Note that the Manifesto is explicitly a privacy document as well as a security one. 4. **Doing threat modeling over talking about it.** A rough model that exists beats an elegant programme design that never runs. 5. **Continuous refinement over a single delivery.** One model handed over once is worth less than a model that keeps getting corrected as the system moves. ### What `over` actually commits you to The common misreading is that the right-hand items are condemned. They are not. Compliance evidence is real and often mandatory. A methodology gives you thoroughness and repeatability. Documents are how understanding is recorded, shared with people who were not present, and measured — one of the Manifesto's own principles puts dialog first precisely *while* giving documents that recording-and-measurement job. The claim is narrower and more useful: when the two conflict, the left-hand item wins, and a practice that consistently sacrifices the left for the right is failing even if every artifact exists. That also means the pairs are falsifiable in a way slogans are not. You can look at a team and say which side it is actually buying. ### Using the pairs as a diagnostic Take a fintech that decides its whiteboard sessions are too informal to audit and replaces them with a mandatory forty-page template that each team fills in alone. Pair two has been inverted: a process has replaced collaboration. The Manifesto predicts what follows, and it is what usually follows. Teams optimise for completing the template rather than for finding anything; the sections that are easy to fill get filled; a document arrives that records what the author already believed on the day they started; and because there was no dialog, nobody else in the room ever built the shared understanding that lets a design change happen. The output volume goes *up* while the number of design issues found goes down — which is exactly why counting completed models is such a treacherous metric. The cure implied by the pair is not to throw the template away. It is to put the conversation back at the centre and let the document record its result, which is the smaller half of the same idea. ### How the values relate to the rest of the document The values say what to prefer. The **anti-patterns** name four recognisable ways real practices fail: Hero Threat Modeler, Admiration for the Problem, Tendency to Overfocus and Perfect Representation. The **patterns** name things that help, including taking a systematic approach and assembling varied viewpoints. Read together, the anti-patterns are mostly what it looks like when a value pair has been inverted — a hero practice has lost `people and collaboration`; a session that only admires the problem has lost `finding and fixing`; a team polishing one diagram forever has lost `doing over talking`. ### Interview register Be able to state the five pairs without hedging, then immediately do something with one. The strong answer moves from recall to application in two sentences: name the pair, name a situation you have seen that inverted it, and say what you would trade to put it back. The weak answer recites the list, or worse, treats the Manifesto as a checklist to audit teams against — which converts the whole document into the checkbox compliance its first pair warns about.

  • A fintech replaces its collaborative sessions with a mandatory forty-page template — which pair does that invert, and what follows?
    It inverts people and collaboration over processes, methodologies and tools. Predictably, teams optimise for completing the template alone, the easy sections get filled, and the document records what its author already believed. Output volume rises while design issues found fall. The fix is not to burn the template but to put the conversation back at the centre and let the document record its result.
  • Does valuing people over processes, methodologies and tools mean STRIDE and structured methods are wrong?
    No. The right-hand item is a lesser good, not a banned one, and the Manifesto separately names a systematic approach and varied viewpoints as patterns that benefit the practice. A method gives you thoroughness and repeatability. The value pair only says that when the method starts substituting for the people who understand the system, you have traded the wrong way.
  • Why does the Manifesto phrase its values as pairs rather than as rules?
    Because it is trying to settle tradeoffs, not prescribe a practice. Every item on both sides is defensible in isolation, so a rule list would either be uselessly vague or would pick a methodology — the thing the authors deliberately refused to do. Pairs also make the document falsifiable: you can look at a real team and say which side it is actually buying.

Like a diet that says vegetables over dessert: dessert is not poison, it just loses when you can only have one.

saying these in an interview costs you the question

  • Claims the Manifesto prescribes STRIDE or any single methodology
  • Says the right-hand items are worthless or forbidden
  • Confuses the five value pairs with the four anti-patterns
  • Treats the Manifesto as a checklist to audit teams against
  • Counts completed models as evidence the values are being met

context