Work through a threat model for a new admin export endpoint
Apply a compact threat-modeling sequence to a high-risk admin export feature.
A new /admin/customer-export endpoint will let internal success admins export customer account records to CSV for escalations and migrations. Asset → actor → abuse path → control → verification The common shortcut is to stop at “it requires login,” which ignores cross-tenant scope, bulk exfiltration, and misuse by a compromised privileged account. Asset Name the high-value asset as customer records in bulk, not merely “an endpoint.” The asset framing matters because volume changes risk. A bulk export can turn ordinary read access into mass exfiltration in one action. Actor Identify likely misuse actors: a compromised support admin, an over-privileged internal…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in