A threat model can only achieve its goal, i.e., to reduce risk and increase security, if there is sufficient buy-in of all the stakeholders involved. Specifically, to implement the playbook, you will need the following resources:
- Time of the people involved in creating the threat model.
- Threat modeling expertise (especially if you are just starting out).
- Time, resources, and authority to address the resulting threats.
As these are important to get management buy-in and commitment to manage your risks with threat modeling. Let us look at these in turn.