Replies: 1 comment
-
No. The STRIDE threat model was done as an outside-in view, and isn't sufficiently detailed to capture the internal architecture of EdgeX. Some of the big changes in EdgeX 3.0, like changing to a different API gateway, or adding internal microservice authentication, wouldn't be reflected in the threat model due to that reason, and are essentially swapping out one component for another. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hello EdgeX community,
I was reading through some of the V3 Migration guides and saw a mention to a STRIDE threat model for EdgeX v3. When referring to the report, it shows a threat model for version 2.2.
Are there any plans to update the model to reflect version 3.0?
Thank you!
Beta Was this translation helpful? Give feedback.
All reactions