OWASP / www-community

OWASP Community Pages are a place where OWASP can accept community contributions for security-related content.

Home Page:https://owasp.org/www-community/

Geek Repo:Geek Repo

Github PK Tool:Github PK Tool

Threat_Modeling_Process missing reference

rfromh opened this issue · comments

commented

Threat_Modeling_Process.md is missing some reference with explanation about Application Security Frame (ASF).

I could not find significant search results on google about ASF. There is no reference in the document. Would it make sense to include a reference to a resource with more details?

commented

Well if you didn’t find something to link then I guess not?

commented

The text should just be edited removing the or clause in that sentence.

commented

The text references this ASF a few times, not only in that one sentence. It seems to be well defined further down but it says ASF has categories "such as", "e.g.". It is not compleley defined in the document.
I see thre options:

  • Find a valid reference to ASF so that the definition is clear.
  • Enhance the definition ASF so that it is complete.
  • Remove this ASF reference completely.
commented

@victoriadrake you're the original creator of this content, thoughts/input?

commented

It seems to be well defined further down but it says ASF has categories "such as", "e.g.".

This document isn’t meant to repeat everything from another source.

My advice is: Either link it if you know the source or drop the references if you don’t.

/ assign

@kingthorin I have already created a PR kindly review it.