# Threat Modeling with Questionnaires

DevFeed: [Threat Modeling with Questionnaires](<https://devfeed.tech/articles/threat-modeling-with-questionnaires-37055.md>)

Original publisher: [Read original article](<https://shostack.org/blog/threat-modeling-with-questionnaires/>)

Author: Adam

Published: 2020-03-19T00:00:00Z

Content type: article

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [Security](<https://devfeed.tech/topics/security.md>), [self-service](<https://devfeed.tech/topics/self-service.md>), [sensitive data](<https://devfeed.tech/topics/sensitive-data.md>)

Tags: [appsec](<https://devfeed.tech/tags/appsec.md>), [security](<https://devfeed.tech/tags/security.md>), [self-service](<https://devfeed.tech/tags/self-service.md>), [sensitive-data](<https://devfeed.tech/tags/sensitive-data.md>)

## AI overview

The article examines lightweight threat modeling through self-service security questionnaires. It argues that developers or scrum masters can identify what they are building, what could go wrong, and whether security engineers should focus on the feature based on its risk.

## Source excerpt

This post comes from a conversation I had on Linkedin with Clint Gibler.