A threat-model is a human-made structured representation of the potential threats targeting a system — capturing assets, vulnerabilities, threat actors, capabilities, motivations, and the attack paths that connect them. It is defined by four parameters: (1) scope — the system boundary and assets under analysis; (2) threat taxonomy — the categories of threat actors and their capabilities; (3) vulnerability mapping — the weaknesses that could be exploited; (4) attack scenarios — the plausible sequences through which an actor could reach a valuable asset. The threat-model persists through documentation (diagrams, attack trees, STRIDE lists), institutional knowledge in security teams, and integration into threat-assessment workflows. [formal: modellum periculi | substrate: behavior | horizon: hours | explicit: yes | epoch: 0.01]
Accepted ontology entry
threat-model
A threat-model is a human-made structured representation of the potential threats targeting a system — capturing assets, vulnerabilities, threat actors, capabilities, motivations, and the attack paths that connect them. It is defined by fo…
Definition
Why it is in scope
The human-made practice of systematically identifying, categorising, and documenting potential threats to a system — its assets, vulnerabilities, threat actors, and attack paths — to inform risk management and security design. Built to persist as documented analysis in security workflows and institutional knowledge.
Names and aliases
- threat-modelen · CANONICAL
Relations from this entry
- cms84mvqm00uuh6s88cc3aflcINSTANCE_OF →
threat-model IS a specific kind of risk analysis focused specifically on identifying and analyzing threats. A competent speaker would say 'a threat model is a type of risk analysis.' The note pins this sense: we're classifying threat-model as a subclass of risk-analysis by scope of concern. Specific→general per Law 9.
- cmrhnc65902098aehuxnv9f0wSERVES →
threat-model is built and maintained for the sake of security. Its designed purpose is to identify and analyze threats so that security measures can be improved. The servant (threat-model) points at the master (security) per Law 8d.
Relations to this entry
No accepted relations in this direction.
Record identity
- Created
- Jul 30, 2026, 11:05 PM UTC
- Content hash
- c0be0e53a54ed8765fcc8729af71e85ccd0789238d48bd16df07060b3d0c1551