נקודה ופסיק; Semicolon<p>Do you have resources on Threat Modeling 3rd party services?</p><p>Most of what I find is about threat modeling your own services, where you (hopefully) can change dev process.</p><p>However that is not always the case, and many times you should threat model 3rd party services that you depend on. <br>I only found this:<br><a href="https://threatmodeler.com/blog/why-threat-modeling-your-third-party-integrations-should-be-standard-practice/" rel="nofollow noopener" translate="no" target="_blank"><span class="invisible">https://</span><span class="ellipsis">threatmodeler.com/blog/why-thr</span><span class="invisible">eat-modeling-your-third-party-integrations-should-be-standard-practice/</span></a></p><p>And would like to find some more resources (whitepapers, articles, books, videos, anything) on the subject.<br> <br>Thanks!</p><p><a href="https://tooot.im/tags/ThreatModeling" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>ThreatModeling</span></a> <a href="https://tooot.im/tags/STRIDE" class="mention hashtag" rel="nofollow noopener" target="_blank">#<span>STRIDE</span></a> </p><p>cc: <span class="h-card" translate="no"><a href="https://infosec.exchange/@adamshostack" class="u-url mention" rel="nofollow noopener" target="_blank">@<span>adamshostack</span></a></span></p>