Mitigations & Status¶
[!NOTE] Required license feature:
threat
Countermeasures for a threat are proposed by the Threat Modeling Agent during its Develop countermeasures stage — typically one to three per threat. They aren't a separate list page — they show up in two places, both driven by the same underlying data:
- On each threat card, in the Data Flow Diagram side panel — the countermeasures for that specific threat, with status and, where the threat was promoted to a risk, a link through to it.
- On the model's Lifecycle dropdown — the "Develop countermeasures" stage row shows whether countermeasures exist yet for the model and lets you (re-)run just that stage.
Once you mark a countermeasure as completed or verified, later agent runs leave it alone.
A threat generated by the agent can be promoted to a risk, with origin "Threat Model Assessment (TMA)". The risk carries its full threat-model context — STRIDE/ENISA categories, CWEs, affected element, trust-boundary crossing, run id and threat id — wherever the risk is viewed or edited.
📸 Screenshot: a threat card in the side panel showing its countermeasures and linked risk.
Related¶
- Data Flow Diagram & Threat Detail — the threat a countermeasure addresses
- Run Modes — re-proposing countermeasures via Develop countermeasures
- Risks — risks the agent raises carry
origin: TMA Assessment