High School AdvancedModule A310 Lessons + Module Test

A3 Threat Modeling

Learn how professional defenders build safe fictional models of assets, actors, entry points, data flows, trust boundaries, misuse possibilities, risk, mitigations, assumptions, and review decisions. The goal is not to predict every problem. The goal is to make better design and risk decisions before uncertainty becomes unmanaged exposure.

Module

A3

Third module in the High School Advanced track.

Lessons

10

Ten threat-modeling lessons plus one module assessment.

Assessment

25

Twenty-five hidden-answer questions after A3.10.

Portfolio

1

One integrated fictional professional threat-model package.

Main Question

How Do Professionals Identify What Could Go Wrong Before Choosing What to Defend?

Threat modeling is a disciplined conversation about fictional mission, assets, actors, interfaces, dependencies, flows, trust, misuse possibilities, uncertainty, risk, and controls. A useful model does not claim to discover every possible threat. It helps teams make traceable decisions, challenge assumptions, prioritize limited effort, select mitigations, and revisit the design when the system or its environment changes.

Understand before ranking

Begin with fictional purpose, assets, actors, workflows, data, dependencies, and trust rather than starting with a generic threat list.

Model decisions, not fear

Describe bounded outcomes, evidence, uncertainty, and controls without exaggeration or operational harmful detail.

Maintain the model

Treat fictional assumptions, mitigations, owners, evidence, and rankings as living decisions that require review when context changes.

Safety Boundary

Threat Modeling Must Remain Fictional, Authorized, Defensive, and Non-Operational

This module includes

  • Invented organizations, systems, identities, assets, actors, interfaces, diagrams, records, assumptions, and decisions.
  • Conceptual threat questions, safe misuse outcomes, risk reasoning, mitigation planning, review, and documentation.
  • Static supplied evidence and portfolio-ready defensive artifacts.

This module does not authorize

  • Accessing, scanning, testing, probing, changing, bypassing, or investigating any real system.
  • Using real credentials, private records, internal diagrams, configurations, logs, supplier data, or recovery details.
  • Writing operational instructions for exploitation, evasion, persistence, credential theft, malware, or destructive action.
Every A3 activity is a planning and reasoning exercise using only supplied fictional information. It does not grant permission to access, test, configure, monitor, investigate, recover, or modify real devices, accounts, networks, applications, cloud services, or organizational systems.

Professional Workflow

Ten Steps from Modeling Purpose to Maintained Decisions

1

Define the decision

State which fictional design, service, change, workflow, or risk decision the model is expected to support.

Required output

Threat-model purpose and decision statement

2

Set scope and boundaries

Document fictional systems, environments, interfaces, teams, data, suppliers, time periods, exclusions, and authorization limits.

Required output

Scope, exclusion, and safety charter

3

Understand the system

Describe the fictional mission, users, critical functions, components, owners, dependencies, data, and expected behavior.

Required output

System context and dependency map

4

Identify assets and actors

Record what requires protection and which fictional human, service, device, workload, supplier, and unknown actors interact with it.

Required output

Asset, actor, owner, and interface register

5

Map flows and trust

Draw fictional information and request flows while marking changes in identity, authority, sensitivity, ownership, location, and control.

Required output

Data-flow and trust-boundary diagram

6

Develop misuse questions

Describe safe, outcome-focused fictional ways that features, workflows, permissions, assumptions, or dependencies could fail or be misused.

Required output

Abuse-case and threat-question library

7

Organize and rank

Group fictional concerns conceptually and rank them using defined impact, likelihood, exposure, control, uncertainty, and mission criteria.

Required output

Prioritized threat-risk register

8

Choose mitigations

Select fictional design, prevention, detection, response, recovery, governance, privacy, and communication controls.

Required output

Mitigation and residual-risk plan

9

Validate and review

Check fictional traceability, assumptions, evidence, owner participation, control coverage, tradeoffs, disagreement, and missing context.

Required output

Review findings and decision log

10

Maintain the model

Define fictional owners, versions, review cadence, change triggers, evidence updates, archived decisions, and model retirement.

Required output

Threat-model lifecycle plan

Module Objectives

What You Will Be Able to Do

Objective 1

Explain threat modeling as a structured defensive decision process rather than a prediction, attack plan, or guarantee.

Objective 2

Define a safe fictional modeling scope with clear purpose, authorization, exclusions, stakeholders, assumptions, and review goals.

Objective 3

Identify fictional assets, actors, interfaces, dependencies, data flows, stores, processes, and meaningful trust boundaries.

Objective 4

Develop safe, non-operational fictional abuse cases and conceptual threat questions without teaching harmful procedures.

Objective 5

Rank fictional threat scenarios using consistent impact, likelihood, exposure, control, uncertainty, and mission criteria.

Objective 6

Choose layered fictional mitigations with owners, dependencies, validation evidence, tradeoffs, and residual-risk decisions.

Objective 7

Document fictional facts, assumptions, hypotheses, unknowns, limitations, confidence, review triggers, and change history.

Objective 8

Build and review a portfolio-ready fictional threat model that is ethical, defensive, traceable, privacy-safe, and useful to multiple audiences.

A3 Lesson Path

Complete All Ten Lessons

Each lesson uses fictional system context, professional defensive reasoning, safe evidence review, hidden-answer checks, and one connected portfolio artifact.

A3.1

Lesson 1 of 10

Why Threat Modeling Exists

Explain threat modeling as a structured defensive process for understanding what matters, what could go wrong, which assumptions require review, and where design effort should be focused before problems occur.

Core skills

  • Explain the purpose and timing of threat modeling
  • Separate threat modeling from prediction and fear-based guessing
  • Connect models to design, review, and risk decisions
  • Define a safe, authorized, fictional modeling scope

Portfolio outcome

Create a fictional threat-model charter with purpose, scope, stakeholders, boundaries, assumptions, and review goals.

A3.2

Lesson 2 of 10

Assets, Actors, and Entry Points

Identify fictional assets that require protection, the human and non-human actors that interact with them, and the approved interfaces through which data, authority, or requests enter a system.

Core skills

  • Classify data, identity, service, operational, and trust assets
  • Distinguish users, administrators, services, suppliers, and unknown actors
  • Document interfaces without testing real systems
  • Connect assets and entry points to owners and business purpose

Portfolio outcome

Build a fictional asset, actor, interface, owner, and dependency register.

A3.3

Lesson 3 of 10

Data Flows and Trust Boundaries

Map how fictional information and requests move between components while marking changes in identity, ownership, sensitivity, authority, location, technology, and control assumptions.

Core skills

  • Create clear fictional data-flow diagrams
  • Recognize meaningful trust changes
  • Label stores, processes, actors, and transfer paths
  • Document validation and evidence needs at boundary crossings

Portfolio outcome

Produce a fictional data-flow and trust-boundary diagram with a boundary review table.

A3.4

Lesson 4 of 10

Abuse Cases and Misuse Thinking

Use safe, non-operational misuse thinking to describe how legitimate features, permissions, workflows, or assumptions might produce harmful outcomes without providing instructions for carrying them out.

Core skills

  • Write outcome-focused fictional abuse cases
  • Avoid operational attack instructions
  • Connect misuse possibilities to assets and controls
  • Include accidental, process, supplier, and insider-related scenarios

Portfolio outcome

Create a fictional abuse-case library with affected assets, preconditions, impact, existing controls, and safe review questions.

A3.5

Lesson 5 of 10

Threat Categories Conceptually

Use conceptual categories to organize defensive questions about identity, integrity, confidentiality, availability, privilege, accountability, privacy, safety, and dependency risk.

Core skills

  • Use categories as prompts rather than proof
  • Avoid forcing every concern into one label
  • Connect categories to system context and evidence
  • Document uncategorized and cross-category concerns

Portfolio outcome

Build a fictional threat-category worksheet that records questions, evidence, affected assets, and model limitations.

A3.6

Lesson 6 of 10

Risk Ranking in Threat Models

Rank fictional threat scenarios using defined likelihood, impact, exposure, control strength, uncertainty, and business-context criteria while keeping assumptions and evidence visible.

Core skills

  • Define consistent fictional ranking scales
  • Separate impact from likelihood and uncertainty
  • Avoid false mathematical precision
  • Record owners, evidence, assumptions, and residual risk

Portfolio outcome

Create a fictional threat-risk matrix with scoring rationale, confidence, uncertainty, and review triggers.

A3.7

Lesson 7 of 10

Choosing Mitigations

Select fictional design, prevention, detection, response, recovery, governance, privacy, and communication safeguards that address causes and outcomes without creating unacceptable new risks.

Core skills

  • Map mitigations to specific modeled concerns
  • Compare prevention, detection, response, and recovery options
  • Identify control dependencies and side effects
  • Assign owners, validation evidence, and completion criteria

Portfolio outcome

Develop a fictional mitigation plan with priorities, owners, dependencies, evidence, tradeoffs, and residual risk.

A3.8

Lesson 8 of 10

Documenting Assumptions and Limits

Record what a fictional model includes, excludes, assumes, cannot verify, and must revisit so readers do not mistake an incomplete planning artifact for a guarantee.

Core skills

  • Separate fact, assumption, hypothesis, and unknown
  • Document scope exclusions and evidence gaps
  • Set expiration dates and review triggers
  • Communicate model confidence without hiding uncertainty

Portfolio outcome

Create a fictional assumptions, exclusions, limitations, unknowns, and review-trigger register.

A3.9

Lesson 9 of 10

Reviewing a Threat Model

Evaluate a fictional threat model for scope, completeness, consistency, evidence, owner participation, decision quality, mitigation traceability, and change readiness.

Core skills

  • Use structured peer and stakeholder review
  • Check traceability from assets to mitigations
  • Find stale assumptions and missing dependencies
  • Document disagreements, decisions, and follow-up owners

Portfolio outcome

Produce a fictional threat-model quality review, issue log, decision record, and revision plan.

A3.10

Lesson 10 of 10

Threat Modeling Workshop Lab

Integrate the complete A3 process in a safe fictional workshop covering scope, assets, actors, entry points, data flows, boundaries, abuse cases, categories, ranking, mitigations, assumptions, and review.

Core skills

  • Facilitate a structured fictional modeling workshop
  • Maintain evidence and decision traceability
  • Balance technical, privacy, service, and leadership perspectives
  • Communicate prioritized outcomes without operational attack detail

Portfolio outcome

Produce a complete fictional threat-model package and leadership-ready defensive summary.

Fictional Evidence Preview

Threat-Model Evidence You Will Learn to Analyze

TM-01

Fictional system-context brief

Observation

A student-services portal supports account access, document submission, counselor review, notifications, and archival storage.

Supports

The model must consider identity, privacy, availability, workflow, storage, notification, and recovery assets.

Does not prove

The brief does not prove how the fictional system is actually configured or monitored.

Modeling use

Use it to establish purpose, stakeholders, critical functions, and initial scope questions.

TM-02

Fictional data-flow diagram

Observation

Uploaded records move from a public interface through validation, processing, storage, review, and archival services.

Supports

Multiple fictional trust, ownership, identity, sensitivity, and technology changes exist.

Does not prove

A diagram alone does not prove every real flow, exception, retry path, or failure mode.

Modeling use

Identify boundary questions, validation needs, evidence sources, and recovery dependencies.

TM-03

Fictional role matrix

Observation

One support role can reset accounts, view submission status, modify notification settings, and initiate archival reprocessing.

Supports

Privilege concentration and separation-of-duty questions deserve review.

Does not prove

The matrix does not prove inappropriate use or effective permission state.

Modeling use

Create identity, approval, monitoring, lifecycle, and recovery threat questions.

TM-04

Fictional change request

Observation

A new supplier integration will receive status updates and return document-processing results.

Supports

The model must address supplier trust, data minimization, validation, availability, logging, and exit planning.

Does not prove

The request does not define the final data fields, controls, contract terms, or operational design.

Modeling use

Record assumptions and require owner decisions before ranking or mitigation selection.

TM-05

Fictional recovery exercise

Observation

The portal returned to service, but delayed notifications caused duplicate submissions and unclear user status.

Supports

Availability, integrity, communication, workflow state, and user-experience concerns are connected.

Does not prove

One exercise does not prove the frequency or full impact of future failures.

Modeling use

Develop abuse cases and mitigations involving degraded service, validation, and communication.

TM-06

Fictional model review note

Observation

The current model lists technical components but omits privacy owners, support workflows, archival deletion, and supplier failure assumptions.

Supports

The model is incomplete across ownership, lifecycle, privacy, and operational dependencies.

Does not prove

The review note does not determine which omitted concern should rank highest.

Modeling use

Open review findings, assign owners, update assumptions, and preserve disagreement.

Threat-Model Risk Preview

Common Modeling Failures You Will Learn to Recognize

Modeling without a decision

Creating a fictional threat list without defining which architecture, change, service, or risk decision the work must support.

Strong control

Begin with a decision statement, success criteria, owner, audience, and review deadline.

Unclear scope

Mixing fictional systems, environments, suppliers, data, and responsibilities without documenting what is included or excluded.

Strong control

Publish a scope map, exclusions, assumptions, boundaries, and authorization statement.

Diagram equals reality

Treating a fictional diagram as complete proof of effective flows, permissions, controls, exceptions, retries, and failures.

Strong control

Link every important claim to evidence, owners, assumptions, confidence, and validation needs.

Category checklist thinking

Using conceptual threat labels mechanically while ignoring business purpose, privacy, safety, workflow, supplier, or recovery context.

Strong control

Use categories as prompts and preserve uncategorized, cross-category, and context-specific concerns.

Operational misuse detail

Writing fictional abuse cases as step-by-step instructions instead of defensive outcome and control questions.

Strong control

Describe affected assets, conditions, outcomes, evidence, and mitigations without procedures for causing harm.

False precision

Presenting fictional numerical rankings as objective truth even when evidence, likelihood, control state, and impact remain uncertain.

Strong control

Define scales, explain rationale, record uncertainty, compare alternatives, and require owner review.

Mitigation without validation

Listing fictional controls without owners, dependencies, completion criteria, evidence, side effects, or residual-risk decisions.

Strong control

Trace every mitigation to a modeled concern and define how design and effectiveness will be reviewed.

Stale threat model

Allowing fictional architecture, suppliers, identities, data, workflows, assumptions, and controls to change while the model remains unchanged.

Strong control

Use versioning, change triggers, review cadence, ownership, archived decisions, and model retirement.

Portfolio Outcome

Build a Complete Fictional Threat-Model Package

By the end of A3, you will have one connected professional threat-model package rather than ten unrelated worksheets. Each lesson strengthens the same fictional case and prepares you for the final workshop lab, review, and leadership communication.

1.Fictional threat-model purpose, decision, scope, authorization, stakeholders, exclusions, and safety boundary
2.System context, mission, critical functions, users, environments, owners, and dependency map
3.Asset register covering data, identity, service, operational, privacy, safety, trust, and recovery value
4.Actor and interface register covering human, service, device, workload, supplier, and unknown actors
5.Data-flow diagram with stores, processes, transfer paths, trust boundaries, validation points, and evidence needs
6.Safe fictional abuse-case and misuse-question library without operational attack instructions
7.Conceptual threat-category worksheet linked to assets, flows, assumptions, evidence, and model limits
8.Threat-risk register with impact, likelihood, exposure, control strength, uncertainty, confidence, and rationale
9.Mitigation map covering design, prevention, detection, response, recovery, governance, privacy, and communication
10.Assumption, exclusion, limitation, unknown, evidence-gap, expiration, and review-trigger register
11.Peer-review findings, disagreement log, decision record, version history, and maintenance plan
12.Leadership summary, technical appendix, portfolio reflection, and full fictionalization statement
Every artifact must use invented organizations, systems, assets, actors, identities, interfaces, data flows, diagrams, risks, evidence, suppliers, dates, decisions, and outcomes. Never upload or reproduce real internal models, credentials, private records, configurations, logs, supplier information, or confidential technical details.

A3 Module Test

Complete the 25-Question Assessment

After A3.10, test your ability to reason about threat-model purpose, assets, actors, entry points, data flows, trust boundaries, abuse cases, conceptual categories, risk ranking, mitigations, assumptions, limitations, review, and lifecycle ownership.

Module Navigation

Begin Threat Modeling

Start with why threat modeling exists before moving through scope, assets, actors, entry points, flows, trust boundaries, abuse cases, categories, risk ranking, mitigations, assumptions, review, and the final workshop lab.