@adamshostack@infosec.exchange
2026-09-18 15:06 UTC
• Title
• Creator, approver
• Client name (ISO 7200 mandates the document’s owner!)
• Date, revision history
• Sheet number and total number of sheets
• Professional seals or stamps (e.g., architect’s license)
• Confidentiality block (typical in technology)
(4/9)
Replies (1)
-
@adamshostack@infosec.exchange 2026-09-18 15:06
Key or Legend A legend can remind the creator to tell a consistent story, and a key unlocks the diagram for the viewer. Which name to use? 🤷 Either one can be used to show all the elements in use, or the unusual ones. If your organization uses DFD3 (https://github.com/adamshostack/DFD3/), there’s no reason to list those elements, but listing the AWS icons is nice, as is listing conventions like “TLS 1.3 unless starred.” I found no reason to prefer either. Key is shorter and I’d look askance at anyone who brought that up in a review meeting. (5/9)