Domain not in remote thumbnail source whitelist: media.infosec.exchange
from Adam Shostack :donor: :rebelverified:
Attached: 1 image
New blog Spatial Reasoning and Threat Modeling
Creating, refining, communicating, and working with models are all important parts of how I think about answering “what are we working on?” People often want to eliminate the diagramming or modeling step as “not required,” and that’s a mistake. The act of engaging with the higher order question of ‘what are we building working on’ is important, and diagramming acts as a forcing function. Committing to a specific representation opens the door to reflecting, criticism or even disagreement, sometimes in counter-productive ways, sometimes ‘merely’ letting the pursuit of perfection distract us.
(1/4)
https://shostack.org/blog/spatial-reasoning-and-threat-modeing/