Right clicking on a dataflow allows you to assign "tags" to the dataflow. These tags are arbitrary string values. Tags that have already been used on dataflows in this, or in other threat models will appear in a drop down list. You can select one of these, or enter a new string value that will become a new tag.
Tags serve two purposes:
1. They act as a visual aid to help understanding the diagram
2. They can trigger rules that will modify the threat model.
A default installation of IriusRisk has no predefined tags, so you would need to define your own. Also, the default knowledge-base included with IriusRisk has no pre-defined rules based on tags. If you need these kinds of rules you should create rules using your tags.
A common use-case for tags is to use them to represent protocols, such as TLS, SSL, HTTP and/or HTTPS. There are no included dataflow rules for these protocols using the tags system. Instead, IriusRisk's default knowledge-base includes questions that relate to the protocol, and the responses to these questions are the triggers to cause Risk Patterns to be imported or removed from the threat model, for example:
Comments
0 comments
Article is closed for comments.