@adamshostack@infosec.exchange
2026-09-24 21:50 UTC
Diagrams are easy, fast, and customizable. You can put any shape you want in, you can break rules such as “no data sinks,” you can slap a boundary through the middle of a process, and ain’t no tooling gonna stop you. Models are harder to build: There are questions about the properties that you’re going to compute on later. You can’t fudge as easily. If you want traceability from model to code (or vice versa), you need to spend time connecting the two, and then maintain those connections. If your model breaks the rules, a model checker can warn you, the same way a compiler can (with the same pros and cons).
(4/9)
Replies (1)
-
@adamshostack@infosec.exchange 2026-09-24 21:50
This dichotomy of “is it worth it” is a theme of the book, because it’s a theme of threat modeling. How do we improve return on investment? The first step is to know where you’re investing. If your diagram tool requires a lot of clicking, then you have to deal with the lots of clicks. And if you need a Visio license before you can start, then there’s both the cash cost and the administrative overhead of getting Visio. Neither adds materially to the quality of a threat model, and so, with investment being higher, the return must be increased as well. (5/9)