« Defining the technology to use in Anvil | Main | Project Planning and Anvil »

Threat Modeling Anvil

At the end of last week I mentioned that the next thing I was planning on doing was some data flow diagrams for Anvil. I decided instead of using Visio and following the typical drawing method that I would use Microsoft's latest version of their Threat Analysis and Modeling Tool. Doing so I get the benefits of Trust Flow Diagrams and Call Flow Diagrams. Problem was, I had to first complete the threat model before I would get the benefits of the diagrams.

At the same time, some other work in the office required my attention for a couple of days, which has made it difficult to keep up with my commitments with Anvil. A regular problem for small companies with over extended resource allocation. I hope I can make up some of that time next week.

During the process of threat modeling over the last couple of days I found a few bugs in the tool and some features I would really like to have that would have made the process easier. I have contacted the ACE team at Microsoft who are responsible for the tool and they are now aware of the bugs and my feature requests. I wouldn't be surprised if I see some fixes coming down the road shortly.

I completed a screencast showing an overview of how I use the tool, and how you too can benefit from it. I still have some work to do on the threat model tonight, but I wanted to make sure I recorded what was going on while I had a chance.

Anvil Threat Model Screencast [Flash ~16MB]

TrackBack

Listed below are links to weblogs that reference Threat Modeling Anvil:

» Does Anvil pass the Joel Test? from Project Anvil
Ever heard of the Joel Test? It's a simple test to measure how well a software team performs. It takes less than 3 minutes to complete, because its a simple yes/no answer test to twelve questions: Do you use source... [Read More]

Comments

Hey Dana, you forgot to add the Threat Analysis tool to your Software list in the right pane.

Good point Jonathon. Link added.

Post a comment

(If you haven't left a comment here before, you may need to be approved by the site owner before your comment will appear. Until then, it won't appear on the entry. Thanks for waiting.)