@adamshostack@infosec.exchange
2026-09-18 15:06 UTC
What’s fixed and what’s in flux
The first question of threat modeling is “what are we working on?” Most systems have elements being worked on in this sprint/this iteration, and elements which are both fixed and worth showing on a diagram. For example, if you’re working on a front end, it might be worth including a load balancer and a database. Show what’s being worked on with hatch-marks, dots, bold lines, or other conventions. Again, the convention you’re using should be in the key unless you have a strongly enforced organizational norm, and the diagram won’t be shared with customers.
(6/9)
Replies (1)
-
@adamshostack@infosec.exchange 2026-09-18 15:06
Map grids The final commonality you can use in a diagram is an old-fashioned map grid. Back when maps were printed on paper, they had grids to help you find a place (“If you’re on page 29, Market street is at F-6.”) As diagrams increase in complexity, a map grid can help people focus on the right part of the diagram. This is most useful as diagrams get bigger, more detailed, or both. (7/9)