OWASP / threat-dragon

An open source threat modeling tool from OWASP
https://owasp.org/www-project-threat-dragon/
Apache License 2.0
881 stars 232 forks source link

Link and reference OWASP cheat sheets #156

Closed jgadsden closed 3 years ago

jgadsden commented 4 years ago

The OWASP project Cheat Sheets provides information on Threat Modeling : https://cheatsheetseries.owasp.org/cheatsheets/Threat_Modeling_Cheat_Sheet.html along with other cheat sheets on various defense topics.

It would be good if these cheat sheets could be referenced by the threat engine

lreading commented 3 years ago

@jgadsden - There's a link at the top of the main page to this cheat sheet. Is this issue closed, or were you thinking of a different implementation?

jgadsden commented 3 years ago

Ah, that link is a start but what I intend to do here is reference the specific cheatsheet and bookmark according to the threat being entered from the diagram.

@lreading Could we keep this one open until this is in place? The cheat sheet is good for adding context to the threat being created

Cheers, Jon

jgadsden commented 3 years ago

I had another look at the Cheat Sheet series and it does not lend itself well to the threat engine. For example there is a cheat sheet on Denial of Service but nothing suitable for the other STRIDE, let alone CIA or LINDDUN

Therefore agreeing with @lreading 's suggestion that this issue can be closed. If in future the cheat sheets become more aligned with the threat engine then that would be a time to open a new issue