(19/N) Let's now turn to the third question of the #ThreatModelingManifesto:
3. What are you going to do about it?
It pays to first establish a few contraints for what you can do, in theory, by #classifying your #assets. Again, for an individual human being, opposed to organizations or companies, it's nearly impossible to impose principles like #ZeroTrust or #NeedToKnow on personal relationships, the closer they get.
So, avoid recycling terms from popular, but less intuitive schemes: Fanciful intelligence labels like “top secret”, “confidential”, or “unclassified” do not tell you what goes into the respective box, and how to handle access to it.
Add another column to your assets spreadsheet, label it "Classification", and pick a more human-centered approach for its values, like:
- For Your Eyes Only (FYEO)
- Intimate
- None Of Your Business (NOYB)
- Shared
- Public
Let's briefly go through these suggestions:
For Your Eyes Only (FYEO)
Assets that are only accessible to, and controlled by nobody but you, because they need to be resilient, even in the face of the closest of your close people misbehaving. Preferably, these assets are kept publicly undetectable and unknown. When you are gone, these assets will be gone, too. FYEO does not make a good default class, though.
Start of this thread:
https://mastodon.de/@tuxwise/113503228291818865