Free Tool

Threat Model Template
one signed artefact for STRIDE enumeration, mitigation decisions, and verification evidence

A free, copy-ready threat model template structured for STRIDE per element, with optional LINDDUN columns for personal-data flows and PASTA stages for high-risk systems. Eight sections covering system scope, asset inventory, trust boundaries and data-flow diagram, STRIDE enumeration per element, mitigation decisions per threat, verification evidence per mitigation, compliance mapping across ISO 27001, SOC 2, PCI DSS, NIST SSDF, OWASP SAMM, and OWASP ASVS, and document control with sign-off and review cadence. Aligned with ISO/IEC 27001 Annex A 8.27, ISO/IEC 27034, SOC 2 CC1.4 and CC7.2, PCI DSS 4.0 Requirement 6.2.4, NIST SSDF practice PW.1, NIST SP 800-30, OWASP SAMM Threat Assessment, OWASP ASVS V1 Architecture Design and Threat Modelling, and the OWASP Application Threat Modeling guidance.

No credit card required. Free plan available forever.

Loading tool...

Carry the threat model on the engagement record, not in a static document folder

SecPortal pairs the signed threat model with the threats it declared as findings, the verification evidence per mitigation, the framework mapping for the audit, and the activity log for the per-revision trail. Free plan available.

No credit card required. Free plan available forever.