From aaa02909b3306f0dde79e9d7ff059081e041acf8 Mon Sep 17 00:00:00 2001 From: Micha Date: Thu, 19 Jan 2023 10:17:00 +0100 Subject: [PATCH 1/2] Add reference to OpenSSF CII project page --- README.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/README.md b/README.md index 44d011f..559f2da 100644 --- a/README.md +++ b/README.md @@ -234,6 +234,8 @@ Contributions welcome. Add links through pull requests or create an issue to sta - [IETF Trans Threat Analysis](https://datatracker.ietf.org/doc/html/draft-ietf-trans-threat-analysis-16) +- [OpenSSF CII Threat Models for Open Source Projects (as part of Silver badge criteria)](https://bestpractices.coreinfrastructure.org/de/projects) + ## Tools *Tools which helps in threat modelling.* From 79fcbe99d8ee5e9bef41132a1931130e88334334 Mon Sep 17 00:00:00 2001 From: Micha Date: Wed, 22 Mar 2023 14:00:12 +0100 Subject: [PATCH 2/2] Incorporate SOC/SIEM guidance --- README.md | 2 ++ 1 file changed, 2 insertions(+) diff --git a/README.md b/README.md index 559f2da..a1873f9 100644 --- a/README.md +++ b/README.md @@ -191,6 +191,8 @@ Contributions welcome. Add links through pull requests or create an issue to sta - [The Enchiridion of Impetus Exemplar: A Threat Modeling Field Guide](https://shellsharks.com/threat-modeling) +- [Leveraging Threat Modeling for your SOC/SIEM](https://www.ncsc.gov.uk/collection/building-a-security-operations-centre/onboarding-systems-and-log-sources/threat-modelling) + ## Threat Model examples