Threat-model workbook¶
The formal record. Written to be checkable – references cited rather than paraphrased.
Not the document the client reads first. That is the front door, and it points into this one rather than restating it.
§1 · How to read this¶
\<What binds, what is reference, and where the front door is.>
§2 · The system¶
2.1 Zones and flows¶
2.2 How collection actually happens¶
2.3 Who is who¶
2.4 The data, and why it is sensitive¶
2.5 Constraints that shape every answer¶
2.6 The trust boundaries, and why there¶
§3 · Scope and assumptions¶
3.1 In scope¶
3.2 Out of scope, and why¶
Each exclusion names where it does live. An exclusion with no home is a silent gap.
3.3 ⚠️ Assumptions the client is asked to confirm or correct¶
One row each. These are the facts the analysis rests on that are not the supplier's to warrant.
§4 · Method¶
4.1 The frame¶
Shostack's four questions: what are we working on · what can go wrong · what are we going to do about it · did we do a good job. Q3 and Q4 are as mandatory as Q2.
4.2 The two question banks¶
4.3 The two spines¶
Security walks the boundaries. Privacy walks the holdings. Deliberately not reconciled.
§5 · The pass¶
5.1 Coverage at a glance¶
Rows are the categories, not the boundaries – the question this answers is was this taxonomy actually walked?
Counts are derived by script, never kept by hand.
5.2 What the pass added¶
The narrative. This is the part anyone reads. Include the predictions that failed.
§6 · Findings register¶
One line per finding. Full entries in Annex B.
§7 · Coverage and limits¶
7.1 What was deliberately not walked¶
7.2 Cross-cutting observations¶
7.3 What remains genuinely open¶
7.4 ⚠️ What this document does not support being claimed¶
There has been no independent review. This work supports one claim – recognised practice was followed and what it found was recorded – and it does not support "reviewed", "assured" or "secure".
A declared gap is defensible; an implied assurance is not.