/notations/security
Security and data flow in Arq
Draw trust boundaries as containers and data flows with their classification. Arq finds every flow that crosses a boundary, flags the ones no control protects, suggests STRIDE threats per crossing and writes the threat report.
/01 Fidelity
L1 Allowed relationships, containment and validation are enforced.
Arq declares a level only when its test fixtures prove it, and raises it the same way.
/02 What you can model
- business
- Business Actor
- data
- Data Store
- application
- Application Component, API
- technology
- Trust Boundary, Node
- security
- Asset, Threat, Threat Actor, Control, Vulnerability, Risk
Preferred relationships: flows to, contains, protects, mitigates, exposes, hosted on, accesses, uses.
/03 Interchange
| Threat report | Markdown, per model |
|---|---|
| SVG and PNG | Export per view |
Every notation draws the same model: an element on this Security / data flow view can appear on views in other notations too. More in the documentation.