Security
Overview
Section titled “Overview”- Primary references: Shostack, Threat Modeling: Designing for Security (Wiley); OWASP, Threat Modeling Cheat Sheet (free)
- Supplementary: SLSA (free); CycloneDX and SPDX SBOM specs (free); OWASP ASVS (free); OWASP, Top 10 for LLM Applications (free)
- Prerequisites: Diagramming & the C4 Model (the data-flow diagram you threat-model), the full system from course Passes 1 to 10
- Estimated time: 1 to 2 weeks in course Pass 11
Key Takeaways
Section titled “Key Takeaways”- Threat modeling asks four questions: what are we building, what can go wrong, what are we going to do about it, and did we do a good job.
- STRIDE per element of a data-flow diagram (spoofing, tampering, repudiation, information disclosure, denial of service, elevation of privilege) makes “what can go wrong” systematic.
- Trust boundaries are where checks belong: every boundary in the system’s interface matrix, including retrieved text reaching a tool call, gets a named control and a test.
- Supply chain is part of the system: an SBOM per artifact and provenance for builds tell you what you shipped when the next CVE lands.
How to Study
Section titled “How to Study”Read the OWASP cheat sheet, then Shostack part I. Draw your system’s data-flow diagram before reading further. In the course, craft.17 writes docs/THREAT_MODEL.md with every trust boundary of your system, craft.18 adds SBOMs and build provenance, and craft.19 reviews secrets handling and authorization paths.
Concepts & Techniques
Section titled “Concepts & Techniques”Core Insight
Section titled “Core Insight”Security is a property of the whole system, so it is reviewed against the whole system’s diagram. The threat model turns the architecture into a list of threats, each tied to a control and a test, and the supply-chain records make the shipped artifacts accountable.
1. Threat modeling your system
Section titled “1. Threat modeling your system”Key ideas:
- DFD: processes, data stores, external entities, data flows, trust boundaries; built from your C4 container view.
- STRIDE per element with a control and an owner per threat, including the RAG-to-tools path (
craft.17).
2. Supply chain, secrets, and authorization
Section titled “2. Supply chain, secrets, and authorization”Key ideas:
- SBOM and provenance for every image and binary (
craft.18). - Secrets and authz review (
craft.19): where keys live (TL_API_KEY, HMAC peppers), how scopes and tenants are checked in the gateway (gw.02).
Course modules
Section titled “Course modules”| Module | Topic | Kind | Pass |
|---|---|---|---|
craft.17 | Threat model (STRIDE on your DFD) | practice | 11 |
craft.18 | SBOM and supply chain | practice | 11 |
craft.19 | Secrets and authz review | practice | 11 |
Chapters
Section titled “Chapters”| # | Module | Chapter | Kind | Pass |
|---|---|---|---|---|
| 1 | craft.17 | Threat model (STRIDE on your DFD) | practice | 11 |
| 2 | craft.18 | SBOM and supply chain | practice | 11 |
| 3 | craft.19 | Secrets and authorization review | practice | 11 |
Connections to Other Tracks
Section titled “Connections to Other Tracks”| Track | Connection |
|---|---|
| Diagramming & the C4 Model | the diagrams the threat model starts from |
| Authorization & Access Control | API keys, scopes, and tenants |
| Usage Policy | abuse cases and their enforcement |
| Professional Responsibility | disclosure when a threat becomes a vulnerability |