---
id: threat
requestedLanguage: zh
descriptionLanguage: zh
---

# 威胁建模 · Threat Modeling

- 类型: 风险分析实践
- 分组: 安全
- 位置: 安全
- [来源](<https://community.owasp.org/Threat_Modeling>)

[HTML](https://dpm.cnonim.name/zh/practices/threat/)

识别资产、潜在威胁、信任边界及应对措施。

## 关系

- 可在其中记录决策: [ADR 架构决策记录 · Architecture Decision Records](/practices/adr/zh.md) (support)
- 可为其定义场景: [DAST 动态安全测试 · Dynamic Application Security Testing](/practices/dast/zh.md) (support)
- 为其具体化威胁: [风险管理 · Software Risk Management](/practices/risk/zh.md) (support)
- 帮助在其中选择缓解措施: [安全编码 · Secure Coding Practices](/practices/securecoding/zh.md) (support)
- 为其设定背景: [安全评审 · Security Architecture Review](/practices/securityreview/zh.md) (support)

[在地图上显示](https://dpm.cnonim.name/#practice=threat&lang=zh)
