Week 10 · overview

Week 10: Threat Modeling Starts With Architecture

Security controls are weak when they are selected before anyone understands the system.

This week starts with architecture: assets, data flows, trust boundaries, identities, dependencies, and required functions. You will build a small threat model for a fictional organization, identify realistic failure or misuse paths, and choose controls that interrupt specific mechanisms instead of decorating a checklist.

This week

  1. You Cannot Defend What You Have Not Modeled — inventory assets, functions, dependencies, and trust boundaries.
  2. Threats Are Paths Through a System — turn architecture into bounded abuse/failure cases without writing exploitation instructions.
  3. Controls Should Break a Mechanism — map preventive, detective, and recovery controls to explicit risks and verify coverage.

Evidence artifact

Create a Threat Model and Control Map containing an architecture sketch, asset table, trust boundaries, at least four bounded threat/failure scenarios, control mappings, residual risk, and one verification plan.