Elektrine lite

← Feed

@adamshostack@infosec.exchange

2026-09-18 15:06 UTC

Key or Legend A legend can remind the creator to tell a consistent story, and a key unlocks the diagram for the viewer. Which name to use? 🤷 Either one can be used to show all the elements in use, or the unusual ones. If your organization uses DFD3 (https://github.com/adamshostack/DFD3/), there’s no reason to list those elements, but listing the AWS icons is nice, as is listing conventions like “TLS 1.3 unless starred.” I found no reason to prefer either. Key is shorter and I’d look askance at anyone who brought that up in a review meeting. (5/9)

Replies (1)

  • What’s fixed and what’s in flux The first question of threat modeling is “what are we working on?” Most systems have elements being worked on in this sprint/this iteration, and elements which are both fixed and worth showing on a diagram. For example, if you’re working on a front end, it might be worth including a load balancer and a database. Show what’s being worked on with hatch-marks, dots, bold lines, or other conventions. Again, the convention you’re using should be in the key unless you have a strongly enforced organizational norm, and the diagram won’t be shared with customers. (6/9)

    Open ##4750077