Skip to content

Conversation

@mike1813
Copy link
Member

Branch 209 should stay open because the plan was to use it for a few more bug fixes.

This pull request is because the first fix is worth having in branch dev, without waiting for other fixes. The first fix adds a signalling control strategy addressing shoulder surfing to access confidential data. It provides a way to fully address the threat when it is not a significant concern. Previously, there was no way to do this.

The changes add the control strategy, which uses a control related to access by a specific process to specific data (i.e., a control associated with an inferred DataAccess asset). The threat patterns were then also updated so this inferred asset is included in the matching pattern.

…rom shoulder surfing while it is being accessed interactively is negligible, due to the limited amount of data exposed at one time via the user interface.
…ategy to make it clear it is a signal to system-modeller, not a security measure.
@mike1813 mike1813 requested a review from samuelsenior October 14, 2025 10:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants