Skip to content

Threat Model Template

Scope and Owners

Identify the capability, owner, version, review date, assets, users, data classifications, and excluded scope.

Trust Boundaries and Data Flows

Document processes, storage, network destinations, authentication, authorization, credentials, external effects, and deletion or rollback boundaries.

Threats and Controls

Threat or abuse case Preconditions Impact Preventive control Detective control Recovery Residual risk Owner

Cover spoofing, tampering, repudiation, disclosure, denial of service, privilege escalation, supply-chain compromise, policy bypass, unsafe automation, and privacy misuse.

Validation

Link security tests, negative tests, fuzzing, dependency review, secret scanning, redaction checks, incident runbooks, accepted risks, and approval.