@adamshostack@infosec.exchange
2026-09-18 15:06 UTC
Key or Legend
A legend can remind the creator to tell a consistent story, and a key unlocks the diagram for the viewer. Which name to use? 🤷 Either one can be used to show all the elements in use, or the unusual ones. If your organization uses DFD3 (https://github.com/adamshostack/DFD3/), there’s no reason to list those elements, but listing the AWS icons is nice, as is listing conventions like “TLS 1.3 unless starred.” I found no reason to prefer either. Key is shorter and I’d look askance at anyone who brought that up in a review meeting.
(5/9)
Replies (1)
-
@adamshostack@infosec.exchange 2026-09-18 15:06
What’s fixed and what’s in flux The first question of threat modeling is “what are we working on?” Most systems have elements being worked on in this sprint/this iteration, and elements which are both fixed and worth showing on a diagram. For example, if you’re working on a front end, it might be worth including a load balancer and a database. Show what’s being worked on with hatch-marks, dots, bold lines, or other conventions. Again, the convention you’re using should be in the key unless you have a strongly enforced organizational norm, and the diagram won’t be shared with customers. (6/9)