# Comparative Assessment via Threat Model

**URL:** <https://threatmodelingconnect.discourse.group/t/comparative-assessment-via-threat-model/156>\
**Category:** The Threat Gazette\
**Tags:** threat-model-library\
**Created:** [September 16, 2024, 11:18am UTC](https://threatmodelingconnect.discourse.group/t/comparative-assessment-via-threat-model/156 "2024-09-16T11:18:38Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dave](https://sea2.discourse-cdn.com/flex002/user_avatar/threatmodelingconnect.discourse.group/dave/32/138_2.png) [@Dave](https://threatmodelingconnect.discourse.group/u/Dave)\
**Post date:** [September 16, 2024, 11:18am UTC](https://threatmodelingconnect.discourse.group/t/comparative-assessment-via-threat-model/156/1 "2024-09-16T11:18:38Z")

</div>

h/t to [CloudSecList](https://cloudseclist.com/issues/issue-255/)

TrailOfBits did a security evaluation of the Cedar, Rego and OpenFGA Policy languages - [Policy Language Security Comparison and TM](https://github.com/trailofbits/publications/blob/master/reports/Policy_Language_Security_Comparison_and_TM.pdf)

Interestingly, they created a threat model to do this comparative analysis. They seem to have defined a generic model that includes systems that use these policy languages, and identified a bunch of threats, and then evaluated how well each policy language mitigated the threats.

I don’t recall seeing threat modelling used as a comparative analysis tool before, but it seems like a good idea!
