Using this method, we should be able to produce a document that gives us a base starting point to talk about security of our system, and help even non-technical people get on the same page to understand what any potential issues are. With this understanding of the system, we can then move forward and focus on the areas that are most important.There are some tools available, here is one from Microsoft. It has some pro's and con's. There isn't much else out there that I know of at the moment in terms of tools that help with Threat Modeling.Here is also a nice article on MSDN about Threat Modeling that is similar to this method I describe.
PS - some terms used in Threat ModelingTerminology
© Copyright 2008, John E. Boal
E-mail