none
SDL 3.1.4: Controlling Threat Generation RRS feed

  • Question

  • Hallo,

    I am using SDL 3.1.4 Tool and I am aware that you can control threat generation for your model

    1) on a per elment base by simply checkboxing "Do not auto generate threats"

    2) on a per threat/element base by selecting certifiy that there are no threats of this type.

    However I have the use case where I want to have something like 2) but for all elements in the model. E.g. I have a model with a lot of elements and I know a specific threat type does not apply to all of my DFD elements. Or in other words can I disable the generation of one or more specific threat type for the whole model (e.g. Repudiation Threat )?

    This would save me a lot of Certifiy Clicking and copy of the same Details/reason why.

    Thanks,

    Markus

    • Moved by Hengzhe Li Tuesday, June 21, 2011 12:05 PM Forum Consolidate (From:Microsoft Security Development Lifecycle (SDL) - Threat Modeling)
    Thursday, August 5, 2010 3:50 PM

Answers

  • Hi Markus,

     

    There is currently no way to do this.  You should consider leaving them all blank, and putting in an assumption that all repuduation is dealt with in XYZ doc.

     

     

    Tuesday, August 24, 2010 5:49 PM

All replies

  • I don't believe there is a way to do that Markus.

    Adam?

     

    Tuesday, August 24, 2010 4:30 AM
  • Hi Markus,

     

    There is currently no way to do this.  You should consider leaving them all blank, and putting in an assumption that all repuduation is dealt with in XYZ doc.

     

     

    Tuesday, August 24, 2010 5:49 PM