Skip to content

How do you consume your reports? (e.g., with Confluence) #1071

Answered by jgadsden
srcnuzn asked this question in General
Discussion options

You must be logged in to vote

From my perspective we store the threat model json file within the source tree
this means the threat model(s) and the source code are generally updated at the same time, but also that the threat models are treated with the same security level as the source code (which is usually highly confidential / business critical)

The PDFs are generally used for review and GRC purposes, but this is just one company's perspective

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@srcnuzn
Comment options

@jgadsden
Comment options

Answer selected by srcnuzn
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
2 participants