Crossposted using Lemmit.

Original post from /r/opsec by /u/Powershillx86 on 2023-05-31 14:06:46+00:00.


How do we think of which models to make? the EFF suggest you ask yourself the following:

  1. What do I have that is worth protecting?
  2. Who do I want to protect is from?
  3. How likely is it that I will need to protect it?
  4. How bad are the consequences if I fail?
  5. How much trouble am I willing to go through to prevent these consequences?

An alternative, but similar set of questions designed for Software threat modeling by Adam Shostack, author of Threat Modeling: Designing for Security

  1. What are you doing? (what info is involved)
  2. What can go wrong? (consider all attack types, recommendation is to use the STRIDE model)
  3. What are you going to do about it? (Identify improvements)
  4. Have you done a good job? (restart the loop)

this post is mostly just to help beginners but it never hurts to brush up on fundamentals!

I have read the rules

not sure if this is the right flair

EDIT: Thank you for the silver :)