Greetings, Almost missed this one while I was out of the office for a couple days... Microsoft have announced the free availability of a threat modeling tool by Frank Swiderski, who is also writing a soon-to-be released book on threat modeling. Details on the tool (warning: requires .NET framework to be installed) as well as the book are available at:
http://www.microsoft.com/downloads/details.aspx?FamilyID=62830f95-0e61-4f87-88a6-e7c663444ac1&displaylang=en Has anyone here tested the tool yet? Opinions? I'm a firm believer that not enough effort is paid to the threat analysis process during the design phase, so any tool that makes that easier should be a good thing -- even if it doesn't run on my Debian/Sarge desktop system. :-) Cheers, Ken van Wyk -- KRvW Associates, LLC http://www.KRvW.com