Hook It to the Things That Change
Last timeDeciding Not to Fix It
A threat model is accurate on the day it is written and wrong within two quarters. Attach it to the changes that invalidate it rather than to a date in a calendar.
Why it goes stale
The document you have produced over the last seven lessons is accurate
today. Within two quarters a good part of it will be wrong, and nothing
will have gone wrong to cause that.
The reasoning does not decay. Severity is still not local, motive still
picks the asset, a chain still fails at its weakest link. What decays is
everything factual the reasoning was applied to.
Four things drift separately. The drawing, because components get added
and nobody updates a diagram. The asset values, because a table that held
names last year holds payment details now. The attacker capabilities,
because a technique that cost a laboratory two years costs anybody a
weekend once it is written up and packaged. And the condition under every
acceptance, each of which was true when written and none of which will
announce its own failure.
The changes that matter
A quarter of engineering work contains perhaps two hundred changes. Five
of them touch the model. The practice stands or falls on being able to
tell which five without reading all two hundred.
The lesson stops here
6 more paragraphs to go
You have read the opening. The rest of the argument, the problems that check whether it landed, and the lines worth keeping at the end all come with a plan.
The first lesson of every course in the library reads the whole way through, free, so you can see exactly what the rest of them are.
See the planThe contentsThis is the reading half
Starting the course gives you your own copy of it. Every idea on every page has problems standing under it, marked with a reason rather than a tick, and any sentence you do not believe can be opened and argued with. None of that can happen on a page nobody owns.
The contents