None
EN
Continuous TRAIL
['Spencer Michaels', 'Paweł Płatek', 'Kelly Kaoudis']
The Trail of Bits Blog
You and your team should incrementally update your threat model as your system changes, integrating threat modeling into each phase of your SDLC to create a Threat and Risk Analysis Informed Lifecycle (TRAIL). Identify the trust zones and components the new threat actor should have privileges to access or interact with, and update your list of threat actor paths. Identify which threat actors have direct access to the trust zones from which this new connection originates, and add them to your list of threat actor paths.