Study. uk . com
  1. Home
  2. All questions
  3. Question 479

CISSP study material · question 479 of 500

Where does OWASP say threat modelling belongs in an agile process, and what should it watch for?

  1. In a separate quarterly workshop run by the security team.
  2. At the end of each release, once the design has stabilised.
  3. Inside ordinary refinement sessions, watching for changes to data flows, access control and other security controls.
  4. In the penetration test scoping meeting, where attack paths are enumerated.
Show the answer

Answer: C. Inside ordinary refinement sessions, watching for changes to data flows, access control and other security controls.

OWASP puts threat modelling inside refinement work, watching for shifts in how data flows and how access is controlled as stories change.

Source: OWASP Top 10 A06:2025 (OWASP) — OWASP Top 10:2025 A06 Insecure Design > Secure Design

Challenge yourself on this topic → Study as cards