The business case · Threat modelling
OWASP Threat Dragon and pytm, by the risk it changes
Two OWASP threat-modelling tools: Threat Dragon draws data-flow diagrams with their threats and remediations, and pytm generates them from a description of the system written as code. Like a behaviour policy, a threat model changes nothing about what the agent can reach. It can replace nobody knows with an answer, as far as the people drawing it know the system.
Open source: Apache-2.0 (Threat Dragon); MIT (pytm) · OWASP · get involved
The deployment: The model's typical deployment, with the answers this project addresses stated as they are without it: nobody knows what it could reach at full speed.
The model: the RiskGraph Explorer's 49 facts, 49 risks and 10 roles, copied into this site with its provenance; the register below is computed, not written. How.