A threat model that fits on an index card
AbstractFour questions from Shostack's framework, kept short enough that a team will actually answer them before shipping.
The four questions
- What are we building? Draw the data-flow diagram. If you cannot draw it, you do not understand it well enough to secure it.
- What can go wrong? Walk the diagram with STRIDE — Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege.
- What are we going to do about it? Each threat gets one of: mitigate, eliminate, transfer, or accept.
- Did we do a good job? Review the diagram against the shipped system.
Why it stays short
The failure mode of threat modeling is the 40-page document nobody reads. Keeping it to one diagram and one table per feature means it gets revisited when the design changes, which is the only time it is worth anything.
| Element | Trust boundary | Top threat |
|---|---|---|
| Browser → API | yes | tampered requests |
| API → database | no | over-broad queries |
| API → third party | yes | data disclosure |
Reference
- Adam Shostack, Threat Modeling: Designing for Security.