skip to content

SDLC Integration and Tooling

How threat modeling survives sprints: what fires a model, who runs the session, keeping it current, and the tools that automate it. Interviewers probe it to spot a one-off done for compliance.

on this pageshow

explore

questions

page 2 of 2

A team's threat model for a new service covers only its two bespoke flows and inherits the platform by reference — when is that delta model legitimate?

level: principalimportance: nice to knowfreq 27%

basics

~20 s

Legitimate when the inherited part is named control by control, each of those controls has evidence behind it, and the team can show why its two flows fall outside the inherited pattern. Lazy when 'the platform handles it' names nothing.

open as a page

Why does reporting raw threat count as a threat modeling metric backfire?

level: principalimportance: nice to knowfreq 34%

basics

~20 s

Threat granularity is the analyst's choice, so the count has no fixed unit and is not comparable across teams. Once it becomes a target, the cheapest way to raise it is splitting one threat into several.

open as a page

How do you record a threat's closure so the ticket re-opens when the design that justified it changes?

level: principalimportance: nice to knowfreq 28%

basics

~20 s

Record the invariant the closure depends on, not just the fix. Name what must stay true, attach a check that fails when it stops being true, and re-open the original ticket rather than filing a new one so the closure history travels with it.

open as a page

Your threat-modeling assistant is a hosted LLM: what must you settle before pasting an unreleased design?

level: principalimportance: nice to knowfreq 31%

basics

~20 s

Settle it as policy, not per engineer: what the contract allows on retention, training and sub-processors, which document classes may leave your tenant, and whether an in-tenant or abstracted draft would do. The reply is a weakness map.

open as a page

showing 31–34 of 34