thread modelling 101 (DE)

Series: [blog security]

I really like the Threat Modeling 101 – Wie fange ich eigentlich an? blogpost from Kevin Peters at CodeCentric for a nice, still high level overview:

Once aware of the threads, the usual options are there: mitigate the weak point, eliminate to get rid of the weak path, shifting responsibility or accepting the risk. Then repeat.