Skip to content

split out into suits #3

Closed
Closed
@jgadsden

Description

@jgadsden

Hello @adamshostack we are thinking of ways to link to the EoP card deck from the OWASP tool Threat Dragon.

TD suggests STRIDE when adding threats to the data flow diagram, and one idea is that when one of STRIDE categories is suggested by TD, then the default description could have a link to the specific EoP suit (so for example if it is Repudiation then we could link to the EoP Repudiation suit). An issue has been raised with TD on this https://github.com/OWASP/threat-dragon-core/issues/25 .

This is not really practical at the moment because if I understand correctly we can link to the pdf with all suits, but not to the individual suit. Linking to a single pdf with all suits will probably be too wide a focus for the users of TD. Could this repo provide the suits split out individually?

It may be that eventually the threat engine in TD could be more sophisticated and suggest a subset of a suit ... but that is some time away :-)

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions