Early Lifecycle Cybersecurity Requirements Development Through Threat Modeling

SEI Report
This report details a threat modeling method for lifecycle cybersecurity risk management, from early design onward, uniting U.S. Air Force and other cybersecurity sources.
Publisher

Software Engineering Institute

DOI (Digital Object Identifier)
10.1184/R1/32180475

Abstract

This report reviews methods and guidelines related to threat modeling and proposes a threat modeling method that meets guidelines from the Department of the Air Force Systems Security Engineering Cyber Guidebook and integrates with well-established cybersecurity knowledge bases, catalogs, and other cybersecurity engineering methods. The proposed threat modeling method can be used during any stage of system acquisition and development. It enables programs to develop early requirements and guidelines for acquisition, identify critical components, make risk-based decisions, refine requirements throughout development, and verify and validate system cybersecurity throughout the lifecycle.

This report also provides an example of using this threat modeling method on a simple system with the commonly used publish-subscribe architectural pattern. The example demonstrates how the method can be used to evaluate cybersecurity threats, damages, and risks associated with architectural options early in a program’s lifecycle.

Cite This SEI Report

Shreve, E., & Schiela, R. (2026, September 10). Early Lifecycle Cybersecurity Requirements Development Through Threat Modeling. Retrieved September 11, 2026, from https://doi.org/10.1184/R1/32180475.

@techreport{shreve_2026,
author={Shreve, Erik and Schiela, Robert},
title={Early Lifecycle Cybersecurity Requirements Development Through Threat Modeling},
month={Sep},
year={2026},
institution={Software Engineering Institute, Carnegie Mellon University},
doi={10.1184/R1/32180475},
url={https://doi.org/10.1184/R1/32180475},
note={Accessed: 2026-Sep-11}
}

Shreve, Erik, and Robert Schiela. "Early Lifecycle Cybersecurity Requirements Development Through Threat Modeling." Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, September 10, 2026. https://doi.org/10.1184/R1/32180475.

E. Shreve, and R. Schiela, "Early Lifecycle Cybersecurity Requirements Development Through Threat Modeling," Software Engineering Institute, Carnegie Mellon University. Software Engineering Institute, 10-Sep-2026 [Online]. Available: https://doi.org/10.1184/R1/32180475. [Accessed: 11-Sep-2026].

Shreve, Erik, and Robert Schiela. "Early Lifecycle Cybersecurity Requirements Development Through Threat Modeling." Software Engineering Institute, Carnegie Mellon University, Software Engineering Institute, 10 Sep. 2026. https://doi.org/10.1184/R1/32180475. Accessed 11 Sep. 2026.

Shreve, Erik; & Schiela, Robert. Early Lifecycle Cybersecurity Requirements Development Through Threat Modeling. Software Engineering Institute. 2026. DOI: 10.1184/R1/32180475. https://doi.org/10.1184/R1/32180475