http://h7isucmawckzflxhipflydxvxpaytk5fozfk5immffg66rhboc74yxyd.onion/doku.php?id=threat_modelling&rev=1565378327&do=diff
The reason you do this is that, without knowing the threats against which you’re trying to protect, you don’t know what mitigations you need to have in place. And, since you probably can’t do everything at once, you’ll need to understand the greatest threats you face, and so which are deserving of the greatest attention, and what measures are “nice to haves”, which could be done at some point in the future.