VICAR: Bridging the Gap Between Threat Modeling and Remediation

@sjgibbs Related to that topic, I posted in this particular post why propose-then-choose is a good style for mitigation planning and how my tool supports that with :white_check_mark: done / :star:favorite / :wastebasket: rejected status selection. When we took a look at AttackTree.online, we learned that they have a fascinating dropdown for mitigation status - see image #8. For simplicity, you can just add a " will do" checkbox or something :slight_smile: Depends on the kind of workshop you intend to support and there’s tradeoffs in keeping the card simple…

1 Like