Which best practice ensures threat modeling remains effective as systems evolve?
Complete it once during initial design
Review and iterate regularly, updating diagrams and mitigations as architecture changes
Delegate it entirely to security teams
Only model external threats
This question is part of this quiz :
Threat Modelling