Threat Modeling: Diving into the Deep End
Jeffrey A. Ingalsbe, Louis Kunimatsu, Tim Baeten, Nancy R. Mead · IEEE Software · 2008
Optimizing the working relationship between a company's IT security (ITS) group and its internal business customers is difficult at best. Who is responsible for security? What does "responsible" mean? For that matter, what does "security" mean? If ITS is solely responsible for security, as is often the case, then everything across the board will likely receive the same level of protection. In their defense, the members of ITS often don't know which asset means the most to the business, so the safest approach is to protect everything as much as possible.