documenting-threats-and-controls

Route security-architecture inputs to local reference sheets for execution.

14|3|Updated Oct 28, 2025
One-click install
npx skills add https://github.com/tachyon-beep/skillpacks --skill documenting-threats-and-controls
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: documenting-threats-and-controls
Source: https://github.com/tachyon-beep/skillpacks/tree/main/plugins/ordis-security-architect/skills/using-security-architect/documenting-threats-and-controls.md
Command: npx skills add https://github.com/tachyon-beep/skillpacks --skill documenting-threats-and-controls

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) components.

What problem does it solve?

Documents threat models and control mappings with traceability, explaining WHY threats exist and HOW controls verify and enforce safety.

Core Features & Use Cases

  • Formats threat descriptions, affected assets, attack scenarios, likelihood, impact, and mitigations
  • Links threats to corresponding controls and evidence
  • Produces clear residual risk and acceptance documentation

Quick Start

Use this to structure threat-model documentation for a new feature: describe threat, affected assets, attack scenarios, and mitigations, then map to controls.

Frequently Asked Questions about documenting-threats-and-controls

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I document threats and map them to security controls?

Document threats by describing the threat, affected assets, attack scenarios, likelihood, and impact, then map each threat to corresponding controls with evidence of verification. This creates traceable threat-to-control linkage with residual risk documentation.

What should be included in a threat model for a new feature?

Structure threat documentation with threat description, affected assets, attack scenarios, and mitigations. Link threats to security controls and compliance requirements to establish traceability and demonstrate how controls verify and enforce safety.

How do I organize threat modeling, controls design, and compliance mapping together?

Route between threat modeling, secure-by-design patterns, security-controls design, security-architecture review, and compliance mapping based on your current task. Each reference sheet addresses a specific security-architecture stage with consistent formatting and control traceability.

Can I use this for security audits and regulatory mapping?

Yes. The approach applies to new designs, design reviews, security audits, and regulatory mapping. Document threats and controls with compliance evidence to satisfy audit requirements and demonstrate control effectiveness across threat scenarios.

What's the difference between documenting threats versus controls separately?

Linked threat-to-control documentation shows why each control exists and how it addresses specific threats and attack scenarios. This traceability clarifies control purpose, prevents orphaned controls, and simplifies compliance and audit evidence collection.

Related Skills