# Threat Modeling

> The activity of listing a flow's assets, trust boundaries and threats, and choosing a mitigation for each threat.

Record: `architecture:threat-modeling`
Kind: activity
Layer: [Security Core](https://banes-lab.com/records/layer/security-core.md)
Severity: contextual
Scope: feature, system, architecture
Canonical: https://banes-lab.com/ontology#architecture-threat-modeling

Listed in [Architecture principles](https://banes-lab.com/api/records/architecture.md), after [Attack Surface Reduction](https://banes-lab.com/records/architecture/attack-surface-reduction.md) and before [Authentication](https://banes-lab.com/records/architecture/authentication.md).

## Repair

- Refactored by: Add Threat Model, Add Mitigation
- Detected by: missing threat model for sensitive flow
- Violated by: security-sensitive change without threat review
- Measured by: threat model coverage
- Enforced by: security review gates

## Requires

- [Assets](https://banes-lab.com/records/lexicon/assets.md)
- [Trust Boundaries](https://banes-lab.com/records/lexicon/trust-boundaries.md)
- [Threat Scenarios](https://banes-lab.com/records/lexicon/threat-scenarios.md)

## Reinforces

- [Security by Design](https://banes-lab.com/records/architecture/security-by-design.md)
- [Risk Management](https://banes-lab.com/records/architecture/risk-management.md)

## Enables

- [Control Selection](https://banes-lab.com/records/lexicon/control-selection.md)

## Conflicts with

- [Assumption-Driven Security](https://banes-lab.com/records/lexicon/assumption-driven-security.md)
- [Security Theater](https://banes-lab.com/records/architecture/security-theater.md)

## In tension with

- [Delivery Speed](https://banes-lab.com/records/lexicon/delivery-speed.md)

## Tensions

- [Threat Modeling / Delivery Speed](https://banes-lab.com/records/tension/delivery-speed-threat-modeling.md)

## Severity

- [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)

## Category

- [Security / Privacy / Compliance / Governance](https://banes-lab.com/records/architecture-category/security-privacy-compliance-governance.md)

## Linked from

- [Anti-patterns](https://banes-lab.com/ontology/principles/architecture-category-anti-patterns.md)
- [Security / Privacy / Compliance / Governance](https://banes-lab.com/ontology/principles/architecture-category-security-privacy-compliance-governance.md)
- [Core Vocabulary](https://banes-lab.com/ontology/lexicon/lexicon-category-core-vocabulary.md)
- [Security Privacy Compliance](https://banes-lab.com/ontology/lexicon/lexicon-category-security-privacy-compliance.md)
- [Severity levels](https://banes-lab.com/ontology/schema/the-vocabulary-severity.md)
- [The resolutions](https://banes-lab.com/ontology/schema/the-resolutions.md)
