# Threat model of a Mobile app

**URL:** <https://threatmodelingconnect.discourse.group/t/threat-model-of-a-mobile-app/1192>\
**Category:** Techniques & Tooling\
**Created:** [November 4, 2025, 10:19am UTC](https://threatmodelingconnect.discourse.group/t/threat-model-of-a-mobile-app/1192 "2025-11-04T10:19:52Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![jlpverwoest](https://avatars.discourse-cdn.com/v4/letter/j/3ab097/32.png) [@jlpverwoest](https://threatmodelingconnect.discourse.group/u/jlpverwoest)\
**Post date:** [November 4, 2025, 10:19am UTC](https://threatmodelingconnect.discourse.group/t/threat-model-of-a-mobile-app/1192/1 "2025-11-04T10:19:52Z")

</div>

There is some pushback from mobile app developers that the creation of a threat model in IRIUS RISK does not work. My question: Doe anybody have any experience and or guidance which could help us?

---

<div class="post-metadata">

**Author:** ![Marc](https://avatars.discourse-cdn.com/v4/letter/m/8dc957/32.png) [@Marc](https://threatmodelingconnect.discourse.group/u/Marc)\
**Post date:** [November 5, 2025, 1:21pm UTC](https://threatmodelingconnect.discourse.group/t/threat-model-of-a-mobile-app/1192/2 "2025-11-05T13:21:02Z")

</div>

Are you looking for just best practices in getting mobile app developers to create threat models in IriusRisk or is the tool having technical issues that is preventing them?

---

<div class="post-metadata">

**Author:** ![jlpverwoest](https://avatars.discourse-cdn.com/v4/letter/j/3ab097/32.png) [@jlpverwoest](https://threatmodelingconnect.discourse.group/u/jlpverwoest)\
**Post date:** [November 7, 2025, 1:53pm UTC](https://threatmodelingconnect.discourse.group/t/threat-model-of-a-mobile-app/1192/3 "2025-11-07T13:53:58Z")

</div>

I am looking for best practices and maybe even an example. Thanks

---

<div class="post-metadata">

**Author:** ![Marco\_Morana](https://sea2.discourse-cdn.com/flex002/user_avatar/threatmodelingconnect.discourse.group/marco_morana/32/524_2.png) [@Marco\_Morana](https://threatmodelingconnect.discourse.group/u/Marco_Morana)\
**Post date:** [November 11, 2025, 3:08pm UTC](https://threatmodelingconnect.discourse.group/t/threat-model-of-a-mobile-app/1192/4 "2025-11-11T15:08:05Z")

</div>

This is a [draw.io](http://draw.io) TM supersimplified of a

[Mobile TM.docx](https://threatmodelingconnect.discourse.group/uploads/short-url/a5vFmagYJS0Y640Ep4mxbybVfrv.docx) (319.8 KB)

mobile app done several years ago

---

<div class="post-metadata">

**Author:** ![TakaharuOgasa](https://avatars.discourse-cdn.com/v4/letter/t/b5e925/32.png) [@TakaharuOgasa](https://threatmodelingconnect.discourse.group/u/TakaharuOgasa)\
**Post date:** [November 14, 2025, 1:02am UTC](https://threatmodelingconnect.discourse.group/t/threat-model-of-a-mobile-app/1192/5 "2025-11-14T01:02:51Z")

</div>

Inspired by Jamil Ahmed’s OWASP Top 10 vs STRIDE mapping. It is quite useful to start conversation with OWASP Top 10 series to map with STRIDE.

Here is an example output of mapping STRIDE with OWASP Mobile Top 10 from ChatGPT. You can custome to suit your environment further. I hope it helps😊

> **[ChatGPT - OWASP Mobile STRIDE Mapping](https://chatgpt.com/share/69167eb4-50dc-8009-9d41-1a078a5b750c)**
>
> Shared via ChatGPT

> **[GitHub - Jamilirkhan/ThreatsLists](https://github.com/Jamilirkhan/ThreatsLists)**
>
> Contribute to Jamilirkhan/ThreatsLists development by creating an account on GitHub.

---

<div class="post-metadata">

**Author:** ![jlpverwoest](https://avatars.discourse-cdn.com/v4/letter/j/3ab097/32.png) [@jlpverwoest](https://threatmodelingconnect.discourse.group/u/jlpverwoest)\
**Post date:** [November 14, 2025, 2:31pm UTC](https://threatmodelingconnect.discourse.group/t/threat-model-of-a-mobile-app/1192/6 "2025-11-14T14:31:41Z")

</div>

Thanks for the responses all!! We have started our journey and was able to convince the teams. I will for sure read and study all the material you shared!
