@adamshostack@infosec.exchange
2026-09-18 15:06 UTC
Diagrams and Common Elements (Threat Model Thursday)
(New blog post: https://shostack.org/blog/diagram-common-elements-threat-model-thursday, this is post 1/9)
Diagrams have a form, such as DFD, swim lane or C4, which is the case even if they deviate from that form’s conventions. They have style (or lack it). But regardless of the form or style of the diagram, they should have a title block and a key (also called a legend). They can also have a convention of how to represent what’s being worked on, and there’s one other common element you should use and I’m not going to make you read the book, but you do have to read this post.
Replies (1)
-
@adamshostack@infosec.exchange 2026-09-18 15:06
Title blocks In my post on Diagrams and Clarity (/blog/clarity-in-diagrams-threat-model-thursday/), I mentioned titles and title blocks, and here I want to talk about those title blocks. (2/9)