Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

update TM stream with remarks #57

Closed
Pat-Duarte opened this issue Nov 9, 2021 · 2 comments
Closed

update TM stream with remarks #57

Pat-Duarte opened this issue Nov 9, 2021 · 2 comments
Assignees
Labels
from old repo Migrated from previous GitHub repo under OWASP summitBoston to discuss

Comments

@Pat-Duarte
Copy link
Contributor

Activity D-TA-1-B.yml
Always make sure to persist the outcome
--> Always persist the outcome

Activity D-TA-2-B.yml
Capture the threat modeling artifacts with tools that are used by your application teams.
--> Capture the threat modeling artifacts with tools used by your application teams.

the developer security culture. Reusable risk patterns,
--> the developer security culture. Reusable risk patterns,

Question D-TA-2-B.yml
Do you use a standard methodology, aligned on your application risk levels?
--> Do you use a standard methodology, aligned with your application risk levels?

You capture the threat modeling artifacts with tools that are used by your application teams
--> You capture the threat modeling artifacts with tools used by your application teams

You regularly (e.g., yearly) review the existing threat models to verify that no new threats are relevant for your applications
--> You review the existing threat models to verify that no new threats are relevant for your applications at least yearly

History from old repo:
@SebaDele opened this issue on Dec 20, 2019
@SebaDele self-assigned this on Dec 20, 2019
@SebaDele added SAMM 2.0 2D1ThreatAssessment streamB labels on Dec 21, 2019
@23bartman commented on Dec 23, 2020
@SebaDele Can you review whether version 2.0 is OK on this ? If not, we can consider finetuning the model.

@Pat-Duarte Pat-Duarte added the from old repo Migrated from previous GitHub repo under OWASP label Nov 9, 2021
@SebaDele SebaDele added the summitBoston to discuss label Nov 6, 2022
@SebaDele
Copy link
Contributor

SebaDele commented Nov 6, 2022

Also to clarify/update difference between Regularly and at least yearly (suggest to switch these - implies updating the scoring for this stream)

@23bartman
Copy link
Contributor

Made the changes, except for the regularly, which is to be covered in issue #60 (and has a wider scope than this issue).

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
from old repo Migrated from previous GitHub repo under OWASP summitBoston to discuss
Projects
Status: Done
Development

No branches or pull requests

3 participants