April 2025 Challenge: What Should an Internal Threat Library Include?

Interesting! :heart_eyes:

Seems like there’s different perspectives on what a threat library is.

Here is mine: Somebody threat modeled a more abstract / generic version of a building block that may be part of your system. We are invited to ask ourselves if that applies to our system: Similar scope? Similar threats? Want to follow suggested mitigations?

Some examples:

We can import stuff from everywhere! :partying_face:

If we build the same things again and again, we should create and reuse a (generic) threat model. :slight_smile: In my opinion threat library is not totally different from threat modeling in general.

1 Like