pasta-objectives

Define business objectives, critical assets, and risk appetite for PASTA threat modeling.

12|1|Updated Feb 9, 2026
One-click install
npx skills add https://github.com/florianbuetow/claude-code --skill pasta-objectives
Or copy as Structured Prompt for Agent
Please help me install this Agent Skill.
Skill: pasta-objectives
Source: https://github.com/florianbuetow/claude-code/tree/main/plugins/appsec/skills/pasta-objectives
Command: npx skills add https://github.com/florianbuetow/claude-code --skill pasta-objectives

SYSTEM DOCUMENTATION & REQUIREMENTS

💡 This Skill includes references (resource) and scripts (resource) components.

What problem does it solve?

This Skill helps define the core business purpose, critical assets, and risk appetite for an application, which is crucial for effective threat modeling.

Core Features & Use Cases

  • Business Context Definition: Establishes what the application protects and why it matters.
  • Asset Identification: Identifies business-critical assets and their sensitivity.
  • Compliance Mapping: Scans for relevant compliance requirements (PCI-DSS, HIPAA, etc.).
  • Risk Appetite Assessment: Helps determine acceptable risk thresholds and business impact.
  • Use Case: Before starting a threat model for a new e-commerce platform, use this Skill to clearly document its purpose, the sensitive customer data it handles, and the acceptable downtime to guide security efforts.

Quick Start

Use the pasta-objectives skill to define the business objectives for the current project.

Frequently Asked Questions about pasta-objectives

High-intent search queries and answers about installing and using this skill.

FAQPage Schema
How do I define business objectives for threat modeling?

To define business objectives for threat modeling, you can establish the application's core purpose, identify critical assets, and determine acceptable risk thresholds using the PASTA methodology. This provides a clear business context to guide security efforts.

How do I identify critical assets and compliance requirements for an application?

Identify critical assets and compliance requirements by analyzing the application's data, user base, and source documentation. This process maps sensitivity levels and regulatory standards like PCI-DSS or HIPAA to your specific business context.

What is risk appetite assessment in PASTA methodology?

Risk appetite assessment in the PASTA methodology determines acceptable risk thresholds and business impact levels. It establishes the maximum tolerable loss and downtime an organization can accept for its critical assets.

Do I need source code access to determine business objectives for threat modeling?

Yes, comprehensive analysis requires access to source code, configuration files, and documentation. These inputs allow the assessment to accurately map application purpose, data handling, and compliance requirements to business objectives.

When should I document business context and risk thresholds for threat modeling?

Document business context and risk thresholds before starting a threat model for a new application or platform. This early documentation ensures security efforts align with acceptable downtime and sensitive data protection requirements.