Threat Model

AWS

Cloud-hosted, with the boundaries a VPC and IAM imply.

Threat Model — AWS: rendered example
Rendered by Gnomon from the source below. No edits.

The source

34 lines of PlantUML, and pulls in C4-PlantUML and Threat modelling. Copy it, or open the template inside Gnomon and render it as it is.

@startuml
!include https://raw.githubusercontent.com/plantuml-stdlib/C4-PlantUML/master/C4_Container.puml
!include <threat/ThreatModel>

title Threat Model — AWS Data Platform

Person(analyst, "Analyst", "Runs reports")

NetworkBoundary(edge, "Internet", "internet") {
  Container(cdn, "Dashboard Delivery", "Amazon CloudFront", "Static assets")
}

TrustBoundary(app, "Application VPC", "medium") {
  Container(gateway, "Public API", "Amazon API Gateway", "Ingest endpoint", $tags="internet_facing+authn_oauth2")
  Container(ingest, "Ingest Handler", "AWS Lambda", "Validates and stores submissions")
}

TrustBoundary(data, "Data VPC", "high") {
  ContainerDb(store, "Operational Store", "Amazon RDS Postgres", "Customer records", "", "pii+encrypted_at_rest+audit_logged")
  ContainerDb(exports, "Raw Exports", "Amazon S3", "Nightly extracts", "", "pii")
  ContainerDb(vault, "Credential Store", "AWS Secrets Manager", "Service credentials", "", "secret+audit_logged")
  ContainerQueue(events, "Event Stream", "Amazon SQS", "Downstream fan-out")
}

Rel(analyst, cdn, "Views dashboards", "HTTPS")
Rel(cdn, gateway, "Calls", "HTTPS", $tags="encrypted")
Rel(gateway, ingest, "Invokes", "HTTPS", $tags="encrypted")
Rel(ingest, store, "Writes", "SQL")
Rel(ingest, exports, "Exports to", "HTTPS", $tags="encrypted")
Rel(ingest, vault, "Fetches credentials", "HTTPS", $tags="encrypted")
Rel(ingest, events, "Publishes", "HTTPS", $tags="encrypted")

THREAT_LEGEND()
@enduml

Render this offline

This template ships in Gnomon and renders on your machine, with no account and nothing sent to a server. The browser editor is free and needs no install.

Get GnomonOpen the browser editor

Others in Threat model diagrams