Threat Modelling: Assets, Adversaries and Trust Boundaries
Security work starts by naming what is worth protecting, who might want it, and where data crosses from a place you control into one you do not. Without that, defences are chosen by habit, and the effort lands away from where the risk is.
What a learner can do afterwards
- Draw a system's trust boundaries and mark every crossing
- List assets and rank them by what their loss would cost
- Match a defence to a named adversary rather than to a general worry
1 · Read
Security starts by naming three things: what is worth protecting, who might want it, and where data crosses out of your control. Without that list, defences get picked by habit and land where the risk is not.
A school mail system names logins and pupil records as assets, with pupil records hurt most if lost. Phishers are the named adversary, sending fake login pages. The defence is checking the sender and never opening login links from mail.
Draw the system and mark every trust boundary, each place data leaves somewhere you control. Rank each asset by what its loss would cost, from a leaked lunch menu up to stolen identities. Then match each defence to one named threat, not to a vague worry.
Test your model with one question per defence: which adversary does this stop. If a defence answers no named threat, move that effort to a crossing that needs it.
Name assets, name adversaries, mark every crossing, and tie each defence to the threat it answers.
2 · Watch
Take it off screen
Where it sits
8 questions wait behind this lesson, each with its answer explained. Every answer feeds the sky: stars light as they are learned, and dim when it is time to come back.