# Better OKRs Through Threat Modeling

DevFeed: [Better OKRs Through Threat Modeling](<https://devfeed.tech/articles/better-okrs-through-threat-modeling-36697.md>)

Original publisher: [Read original article](<https://shostack.org/blog/better-oks-through-threat-modeling/>)

Author: Adam

Published: 2021-02-15T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>)

Tags: [appsec](<https://devfeed.tech/tags/appsec.md>), [okrs](<https://devfeed.tech/tags/okrs.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [security](<https://devfeed.tech/tags/security.md>)

## AI overview

This commentary argues that effective threat modeling can improve application security OKRs and help define a strategic AppSec roadmap. It proposes sample objectives involving current threat-model documents, system resilience, security testing, and reducing security debt.

## Source excerpt

Effective Threat Modeling by itself can ensure that your OKRs and AppSec Program are not only in great tactical shape, but also help define a strategic roadmap for your AppSec Program.