{"id":78856,"date":"2026-10-04T05:08:21","date_gmt":"2026-10-04T05:08:21","guid":{"rendered":"https:\/\/www.devopsschool.com\/blog\/?p=78856"},"modified":"2026-10-04T05:08:22","modified_gmt":"2026-10-04T05:08:22","slug":"threat-modeling-owasp-threat-dragon","status":"publish","type":"post","link":"https:\/\/www.devopsschool.com\/blog\/threat-modeling-owasp-threat-dragon\/","title":{"rendered":"Threat Modeling + OWASP Threat Dragon"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\">1. What is Threat Modeling?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In the simplest words:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Threat modeling is the process of looking at an application before or during development and asking: &#8220;How can this system be attacked, what could go wrong, and how can we prevent it?&#8221;<\/strong><\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Think of it as a <strong>security review of your application design<\/strong>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">Normal development thinking<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A developer may think:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">&#8220;How do I make this feature work?&#8221;<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Threat modeling adds:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">&#8220;How could someone misuse or attack this feature?&#8221;<\/p>\n<\/blockquote>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">2. Simple Example<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Imagine you&#8217;re building an online shopping application:<\/p>\n\n\n<pre class=\"wp-block-code\"><span><code class=\"hljs\">Customer\n   |\n   \u2193\nWeb Application\n   |\n   \u2193\nDatabase<\/code><\/span><\/pre>\n\n\n<p class=\"wp-block-paragraph\">A developer thinks:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">Customer logs in \u2192 browses products \u2192 places order \u2192 data goes into database.<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">A security engineer asks:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">What if someone sends a fake request?<\/p>\n<\/blockquote>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">What if someone steals another user&#8217;s session?<\/p>\n<\/blockquote>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">What if someone modifies the price?<\/p>\n<\/blockquote>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">What if someone accesses the database directly?<\/p>\n<\/blockquote>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">What if someone sends thousands of requests and brings the application down?<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Those questions are <strong>threat modeling<\/strong>.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">3. Threat Modeling in One Sentence<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Remember this:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Threat Modeling = Understand the system \u2192 Identify what can go wrong \u2192 Assess the risk \u2192 Decide how to protect it.<\/strong><\/p>\n<\/blockquote>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">4. When Should We Do Threat Modeling?<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Ideally, <strong>before the application is built<\/strong>.<\/p>\n\n\n<pre class=\"wp-block-code\"><span><code class=\"hljs\">Requirement\n     \u2193\nArchitecture\n     \u2193\n\ud83d\udee1\ufe0f Threat Modeling\n     \u2193\nDevelopment\n     \u2193\nTesting\n     \u2193\nDeployment\n     \u2193\nProduction<\/code><\/span><\/pre>\n\n\n<p class=\"wp-block-paragraph\">But you can also perform it on an existing application.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It&#8217;s particularly useful when:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Designing a new application<\/li>\n\n\n\n<li>Adding a major feature<\/li>\n\n\n\n<li>Adding a new API<\/li>\n\n\n\n<li>Introducing a payment system<\/li>\n\n\n\n<li>Adding a third-party service<\/li>\n\n\n\n<li>Changing authentication<\/li>\n\n\n\n<li>Moving to cloud\/Kubernetes<\/li>\n\n\n\n<li>Handling sensitive information<\/li>\n\n\n\n<li>Changing architecture<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">5. What is OWASP Threat Dragon?<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Now introduce the tool.<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>OWASP Threat Dragon is an open-source tool that helps you perform and document threat modeling visually.<\/strong><\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">The important point:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Threat Dragon does not replace threat modeling.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">It helps you <strong>draw the system, identify threats, document them, and track mitigations.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Think:<\/p>\n\n\n<pre class=\"wp-block-code\"><span><code class=\"hljs\">Threat Modeling\n      +\nThreat Dragon\n      \u2193\nVisual + Documented Threat Model<\/code><\/span><\/pre>\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">6. Why Not Just Use Excel?<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Excellent question\u2014and this should actually be discussed in a good tutorial.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You absolutely <strong>can use Excel, Notion, Markdown, Miro, etc.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Threat<\/th><th>Risk<\/th><th>Mitigation<\/th><\/tr><\/thead><tbody><tr><td>SQL Injection<\/td><td>High<\/td><td>Parameterized queries<\/td><\/tr><tr><td>Data leakage<\/td><td>High<\/td><td>Encryption<\/td><\/tr><tr><td>Unauthorized access<\/td><td>High<\/td><td>RBAC<\/td><\/tr><tr><td>DoS<\/td><td>Medium<\/td><td>Rate limiting<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">That&#8217;s perfectly valid.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But when the architecture becomes larger:<\/p>\n\n\n<pre class=\"wp-block-code\"><span><code class=\"hljs\">Internet\n   \u2193\nCloudFront\n   \u2193\nWAF\n   \u2193\nALB\n   \u2193\nEKS\n \u250c\u2500\u253c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2510\n \u2193 \u2193               \u2193\nAPI Redis          Worker\n \u2193                  \u2193\nRDS                S3\n \u2193\nPayment Gateway<\/code><\/span><\/pre>\n\n\n<p class=\"wp-block-paragraph\">visual modeling becomes much more useful.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Threat Dragon helps you <strong>see the system and the security boundaries<\/strong>, rather than just maintaining a list.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">7. The Core Threat Modeling Process<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">A practical gold-standard workflow is:<\/p>\n\n\n<pre class=\"wp-block-code\"><span><code class=\"hljs\">1. Understand the system\n          \u2193\n2. Draw the architecture\n          \u2193\n3. Identify trust boundaries\n          \u2193\n4. Identify assets\/data\n          \u2193\n5. Identify threats\n          \u2193\n6. Analyze risk\n          \u2193\n7. Define mitigations\n          \u2193\n8. Document\n          \u2193\n9. Review\n          \u2193\n10. Update when architecture changes<\/code><\/span><\/pre>\n\n\n<p class=\"wp-block-paragraph\">This is more important than learning the Threat Dragon buttons.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">8. Step 1 \u2014 Understand the System<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Before opening Threat Dragon, understand what you&#8217;re building.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Online Banking Application<\/strong><\/p>\n\n\n<pre class=\"wp-block-code\"><span><code class=\"hljs\">User\n \u2193\nWeb Application\n \u2193\nAuthentication Service\n \u2193\nBanking API\n \u2193\nDatabase<\/code><\/span><\/pre>\n\n\n<p class=\"wp-block-paragraph\">Ask:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Who uses the system?<\/li>\n\n\n\n<li>What data does it handle?<\/li>\n\n\n\n<li>What are the important components?<\/li>\n\n\n\n<li>Which systems are external?<\/li>\n\n\n\n<li>Where does sensitive data travel?<\/li>\n\n\n\n<li>Who can access what?<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">9. Step 2 \u2014 Draw the System<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Now create a Data Flow Diagram (DFD).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example:<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"> <code>                   Internet\n                       |\n                       \u2193\n                   [User]\n                       |\n                       \u2193\n                 [Web Server]\n                       |\n                       \u2193\n                    [API]\n                    \/   \\\n                   \/     \\\n                  \u2193       \u2193\n              [Database] [Payment API]<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">This is where Threat Dragon becomes useful.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">10. Step 3 \u2014 Identify Trust Boundaries<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">This is one of the most important concepts.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A <strong>trust boundary<\/strong> is a place where the level of trust changes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example:<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"> <code>          INTERNET\n              |\n================================\n        TRUST BOUNDARY\n================================\n              |\n          Application\n              |\n================================\n        TRUST BOUNDARY\n================================\n              |\n           Database<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">For example:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Internet \u2192 Application<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The Internet is untrusted.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Your application cannot simply trust everything coming from the Internet.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">11. Step 4 \u2014 Identify Important Assets<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Ask:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">&#8220;What are we trying to protect?&#8221;<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Examples:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Passwords<\/li>\n\n\n\n<li>Personal information<\/li>\n\n\n\n<li>Credit-card information<\/li>\n\n\n\n<li>API keys<\/li>\n\n\n\n<li>Authentication tokens<\/li>\n\n\n\n<li>Customer records<\/li>\n\n\n\n<li>Business data<\/li>\n\n\n\n<li>Source code<\/li>\n\n\n\n<li>Financial transactions<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">These are your <strong>assets<\/strong>.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">12. Step 5 \u2014 Identify Threats<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Now ask:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>&#8220;What could an attacker do?&#8221;<\/strong><\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">This is where <strong>STRIDE<\/strong> becomes useful.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">STRIDE<\/h2>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Letter<\/th><th>Threat<\/th><th>Simple Question<\/th><\/tr><\/thead><tbody><tr><td><strong>S<\/strong><\/td><td>Spoofing<\/td><td>Can someone pretend to be another user?<\/td><\/tr><tr><td><strong>T<\/strong><\/td><td>Tampering<\/td><td>Can someone modify data?<\/td><\/tr><tr><td><strong>R<\/strong><\/td><td>Repudiation<\/td><td>Can someone deny an action?<\/td><\/tr><tr><td><strong>I<\/strong><\/td><td>Information Disclosure<\/td><td>Can someone access private information?<\/td><\/tr><tr><td><strong>D<\/strong><\/td><td>Denial of Service<\/td><td>Can someone make the system unavailable?<\/td><\/tr><tr><td><strong>E<\/strong><\/td><td>Elevation of Privilege<\/td><td>Can someone gain unauthorized privileges?<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<h3 class=\"wp-block-heading\">Example<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">For:<\/p>\n\n\n<pre class=\"wp-block-code\"><span><code class=\"hljs\">User \u2192 Login API<\/code><\/span><\/pre>\n\n\n<p class=\"wp-block-paragraph\">you might identify:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Spoofing<\/strong><\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">Attacker obtains another user&#8217;s credentials and logs in.<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Mitigation:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">MFA + strong authentication + session controls.<\/p>\n<\/blockquote>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">13. Step 6 \u2014 Analyze the Risk<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Not every threat has the same importance.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Threat<\/th><th>Likelihood<\/th><th>Impact<\/th><th>Priority<\/th><\/tr><\/thead><tbody><tr><td>SQL Injection<\/td><td>High<\/td><td>High<\/td><td>\ud83d\udd34 Critical<\/td><\/tr><tr><td>Information disclosure<\/td><td>Medium<\/td><td>High<\/td><td>\ud83d\udfe0 High<\/td><\/tr><tr><td>DoS<\/td><td>Medium<\/td><td>Medium<\/td><td>\ud83d\udfe1 Medium<\/td><\/tr><tr><td>Minor UI issue<\/td><td>Low<\/td><td>Low<\/td><td>\ud83d\udfe2 Low<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The purpose isn&#8217;t to create <strong>100 threats just because you can<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The goal is:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Find the threats that actually matter and prioritize them.<\/strong><\/p>\n<\/blockquote>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">14. Step 7 \u2014 Define Mitigations<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">For every meaningful threat, ask:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>&#8220;What are we going to do about it?&#8221;<\/strong><\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">Example:<\/p>\n\n\n<pre class=\"wp-block-code\"><span><code class=\"hljs\">Threat:\nSQL Injection\n\nRisk:\nHigh\n\nMitigation:\n- Parameterized queries\n- ORM\n- Input validation\n- Least-privilege database account\n- Security testing<\/code><\/span><\/pre>\n\n\n<p class=\"wp-block-paragraph\">Another:<\/p>\n\n\n<pre class=\"wp-block-code\"><span><code class=\"hljs\">Threat:\nCredential theft\n\nMitigation:\n- MFA\n- Password hashing\n- Secure session management\n- Rate limiting\n- Account lockout\/risk controls<\/code><\/span><\/pre>\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">15. Step 8 \u2014 Put It Into Threat Dragon<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Now the tool becomes useful.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">You create your model and add components such as:<\/p>\n\n\n<pre class=\"wp-block-code\"><span><code class=\"hljs\">User\nProcess\nData Store\nExternal Entity\nData Flow\nTrust Boundary<\/code><\/span><\/pre>\n\n\n<p class=\"wp-block-paragraph\">Then document threats against the relevant components or data flows.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For example:<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"> <code>                User\n                   |\n                   | HTTPS\n                   \u2193\n              \u250c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2510\n              \u2502   API   \u2502\n              \u2514\u2500\u2500\u2500\u2500\u252c\u2500\u2500\u2500\u2500\u2518\n                   |\n                   | SQL\n                   \u2193\n              \u250c\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2510\n              \u2502   RDS   \u2502\n              \u2514\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2500\u2518\n\nThreat:\nSQL Injection\n\nMitigation:\nParameterized queries<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Now you have an <strong>architecture + threats + mitigations<\/strong> in one model.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">16. What Threat Dragon Should NOT Become<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">This is very important for a gold-standard tutorial.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Don&#8217;t teach:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\">&#8220;Every project must have a 200-page threat model.&#8221;<\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">\u274c That&#8217;s bureaucracy.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Instead:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Threat modeling should be proportional to the risk and complexity of the system.<\/strong><\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">A small internal application might need:<\/p>\n\n\n<pre class=\"wp-block-code\"><span><code class=\"hljs\">30-minute threat-modeling exercise\n+\nsimple checklist<\/code><\/span><\/pre>\n\n\n<p class=\"wp-block-paragraph\">A large banking platform might require:<\/p>\n\n\n<pre class=\"wp-block-code\"><span><code class=\"hljs\">Multiple architecture diagrams\n+\ntrust boundaries\n+\ndetailed threat analysis\n+\nrisk assessment\n+\nmitigation tracking\n+\nsecurity review<\/code><\/span><\/pre>\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">17. The DevSecOps Connection<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">Threat modeling fits <strong>very early<\/strong> in DevSecOps.<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"> <code>                DEVSECOPS\n\nPlan\n \u2193\nRequirements\n \u2193\n\ud83c\udff0 Threat Modeling\n \u2193\nDesign\n \u2193\nCode\n \u2193\nSAST\n \u2193\nSCA\n \u2193\nBuild\n \u2193\nContainer Security\n \u2193\nIaC Security\n \u2193\nDAST\n \u2193\nDeploy\n \u2193\nRuntime Security\n \u2193\nMonitoring<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">Notice something important:<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Threat modeling happens before most security testing.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Why?<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Because testing can find vulnerabilities in an implementation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Threat modeling can identify <strong>security problems in the design itself<\/strong>.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">18. Threat Modeling vs SAST vs SCA<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">This distinction is excellent for students:<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Practice<\/th><th>Main Question<\/th><\/tr><\/thead><tbody><tr><td><strong>Threat Modeling<\/strong><\/td><td>How could our system be attacked?<\/td><\/tr><tr><td><strong>SAST<\/strong><\/td><td>Is there a security problem in our source code?<\/td><\/tr><tr><td><strong>SCA<\/strong><\/td><td>Are our third-party dependencies vulnerable?<\/td><\/tr><tr><td><strong>DAST<\/strong><\/td><td>Can our running application be attacked?<\/td><\/tr><tr><td><strong>Container Security<\/strong><\/td><td>Is our container\/image secure?<\/td><\/tr><tr><td><strong>IaC Security<\/strong><\/td><td>Is our infrastructure configuration secure?<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">So:<\/p>\n\n\n<pre class=\"wp-block-code\"><span><code class=\"hljs\">Threat Modeling\n      \u2193\nFind design-level risks\n\nSAST\n      \u2193\nFind code-level risks\n\nSCA\n      \u2193\nFind dependency risks\n\nDAST\n      \u2193\nFind runtime\/application risks<\/code><\/span><\/pre>\n\n\n<p class=\"wp-block-paragraph\">They complement each other.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h1 class=\"wp-block-heading\">19. The Golden Mental Model<\/h1>\n\n\n\n<p class=\"wp-block-paragraph\">If you&#8217;re teaching this, I&#8217;d make students remember this:<\/p>\n\n\n\n<pre class=\"wp-block-preformatted\"> <code>            THREAT MODELING\n\n          \"What are we building?\"\n                    \u2193\n          \"What do we need to protect?\"\n                    \u2193\n          \"How could it be attacked?\"\n                    \u2193\n          \"What is the risk?\"\n                    \u2193\n          \"How will we mitigate it?\"\n                    \u2193\n          \"Did we document it?\"\n                    \u2193\n          \"Did the architecture change?\"\n                    \u2193\n                 Repeat<\/code><\/pre>\n\n\n\n<p class=\"wp-block-paragraph\">And finally:<\/p>\n\n\n\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\">\n<p class=\"wp-block-paragraph\"><strong>Threat Dragon is the tool. Threat modeling is the security practice.<\/strong><\/p>\n<\/blockquote>\n\n\n\n<p class=\"wp-block-paragraph\">That&#8217;s the distinction I&#8217;d make very clear in a professional DevSecOps course.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>1. What is Threat Modeling? In the simplest words: Threat modeling is the process of looking at an application before or during development and asking: &#8220;How can&#8230; <\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_joinchat":[],"footnotes":""},"categories":[11138],"tags":[],"class_list":["post-78856","post","type-post","status-publish","format-standard","hentry","category-best-tools"],"_links":{"self":[{"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/posts\/78856","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/comments?post=78856"}],"version-history":[{"count":1,"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/posts\/78856\/revisions"}],"predecessor-version":[{"id":78857,"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/posts\/78856\/revisions\/78857"}],"wp:attachment":[{"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/media?parent=78856"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/categories?post=78856"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.devopsschool.com\/blog\/wp-json\/wp\/v2\/tags?post=78856"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}