VICAR: Bridging the Gap Between Threat Modeling and Remediation

I like the VICAR-structure that you provide @LFB !

What’s your concept of an actor? Does this comprise the preconditions?

I’ve experimented with structures such as Attacker with [preconditions / actor?] achieves [postconditions / impact] by [attack / vector]. See also :fast_forward_button: GIVEN WHEN THEN Threat Modeling. You add the So we will [control] with prio [ranking].

We seem to have similar thoughts here… :slight_smile: