Week 10 · overview
Week 10: Threat Modeling Starts With Architecture
Security controls are weak when they are selected before anyone understands the system.
This week starts with architecture: assets, data flows, trust boundaries, identities, dependencies, and required functions. You will build a small threat model for a fictional organization, identify realistic failure or misuse paths, and choose controls that interrupt specific mechanisms instead of decorating a checklist.
This week
- You Cannot Defend What You Have Not Modeled — inventory assets, functions, dependencies, and trust boundaries.
- Threats Are Paths Through a System — turn architecture into bounded abuse/failure cases without writing exploitation instructions.
- Controls Should Break a Mechanism — map preventive, detective, and recovery controls to explicit risks and verify coverage.
Evidence artifact
Create a Threat Model and Control Map containing an architecture sketch, asset table, trust boundaries, at least four bounded threat/failure scenarios, control mappings, residual risk, and one verification plan.