Skip to content

Threat Modelling

What is Threat Modelling?

A structured approach for identifying, quantifying, and addressing security threats to a system or application. Threat modelling analyses potential attack vectors and helps prioritise security controls during the design phase.

Information Security

Each of these is named in at least one of the same controls as threat modelling. The number is how many controls name both.

What the standards actually require on threat modelling

Requirements naming threat modelling across 6 standards, quoted from the control text.

OWASP ASVS1 control

Per OWASP ASVS V1: ensure verified application architecture + secure design + threat modelling. Requirements include (a) maintain documented secure software development lifecycle (SDLC) including security activities at requirements + design + implementation +...

OWASPASVS-1 · Architecture, Design and Threat Modelling (V1)

Per OWASP DSOMM Implementation dimension: implement secure software development practices. Requirements include (a) maintain secure coding standards aligned to language + framework + with developer guidance + (b) conduct threat modelling at design phase + revi...

DSOMM-2 · Implementation Practices, Secure Coding, and Threat Modelling

Perform threat modelling to identify potential threats and enumerate mitigating controls, covering both the running application and the artefacts and pipeline that produce it.

ASBv3-DS-1 · Conduct threat modeling

Software development shall follow a secure SDLC integrating threat modelling, secure coding, code review and security testing prior to release.

CON.8 · Software Development
BSIMM1 control

Architecture Analysis. Threat modelling/architecture analysis using STRIDE or an equivalent method is performed so design-level risks are identified.

AA2.1 · Perform architecture analysis using STRIDE or equivalent

Questions people ask about threat modelling

What is Threat Modelling?
A structured approach for identifying, quantifying, and addressing security threats to a system or application. Threat modelling analyses potential attack vectors and helps prioritise security controls during the design phase.
Why is Threat Modelling important for compliance?
Threat Modelling is a key concept in Information Security. Understanding threat modelling helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Threat Modelling?
Threat Modelling appears in the requirement text of OWASP ASVS, OWASP DevSecOps Maturity Model (DSOMM), Azure Security Benchmark, BSI IT-Grundschutz, BSIMM. Across these standards we have identified 6 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Threat Modelling?
Explore our compliance framework pages to see how threat modelling applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Threat Modelling applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.