tuxwise<p>(19/N) Let's now turn to the third question of the <a href="https://mastodon.de/tags/ThreatModelingManifesto" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ThreatModelingManifesto</span></a>: </p><p><strong>3. What are you going to do about it?</strong></p><p>It pays to first establish a few contraints for what you can do, in theory, by <a href="https://mastodon.de/tags/classifying" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>classifying</span></a> your <a href="https://mastodon.de/tags/assets" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>assets</span></a>. Again, for an individual human being, opposed to organizations or companies, it's nearly impossible to impose principles like <a href="https://mastodon.de/tags/ZeroTrust" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ZeroTrust</span></a> or <a href="https://mastodon.de/tags/NeedToKnow" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>NeedToKnow</span></a> on personal relationships, the closer they get.</p><p>So, avoid recycling terms from popular, but less intuitive schemes: Fanciful intelligence labels like “top secret”, “confidential”, or “unclassified” do not tell you what goes into the respective box, and how to handle access to it.</p><p>Add another column to your assets spreadsheet, label it "Classification", and pick a more human-centered approach for its values, like:</p><ul><li>For Your Eyes Only (FYEO)</li><li>Intimate</li><li>None Of Your Business (NOYB)</li><li>Shared</li><li>Public</li></ul><p>Let's briefly go through these suggestions:</p><p><strong>For Your Eyes Only (FYEO)</strong></p><p>Assets that are only accessible to, and controlled by nobody but you, because they need to be resilient, even in the face of the closest of your close people misbehaving. Preferably, these assets are kept publicly undetectable and unknown. When <em>you</em> are gone, these assets will be gone, too. FYEO does not make a good default class, though.</p><p>Start of this thread:<br><a href="https://mastodon.de/@tuxwise/113503228291818865" translate="no" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://</span><span class="ellipsis">mastodon.de/@tuxwise/113503228</span><span class="invisible">291818865</span></a></p><p><a href="https://mastodon.de/tags/ThreatModeling" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ThreatModeling</span></a> <a href="https://mastodon.de/tags/4D" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>4D</span></a></p>