For each component in a design, walk through STRIDE. What can an attacker do here? What mitigates it?
Output: ranked risks with owners and dates. Threat modeling is an architecture activity, not a security-team-only chore.
Spoofing, Tampering, Repudiation, Info Disclosure, DoS, Elevation of Privilege.

For each component in a design, walk through STRIDE. What can an attacker do here? What mitigates it?
Output: ranked risks with owners and dates. Threat modeling is an architecture activity, not a security-team-only chore.
Key takeaways