TRA Studio

Getting started

Learn TRA Studio by doing it

Step-by-step walkthroughs of the real product, each one taking a worked example from an empty workspace to something you could hand to an auditor.

Start here

The first walkthrough is the one to read if you read only one: it is a complete pass through the tool — product, TRA, system model, threats, treatments, report. Everything else in TRA Studio is a variation on that loop, so the later walkthroughs assume you have been through it.

The walkthroughs

Every picture is a screenshot of the running application, re-captured whenever the interface changes.

From a product to a finished report

One complete pass through TRA Studio: create a product, set up its TRA, model the system, derive the threats, decide a treatment, print the report.

Time: About 45 minutes

What you do

  1. Create a product and classify it under the CRA
  2. Set up the TRA project, its target area and its members
  3. Model the system — trust boundaries, components, data flows
  4. Generate the threats from the model, and rate one yourself
  5. Decide and record a treatment, with its residual risk
  6. Read the risk posture and produce the report
Start the walkthrough

Also planned in this chapter

Written in this order. Each builds on the first walkthrough rather than repeating it.

  1. Bring in an existing threat model

    Import a Microsoft Threat Modeling Tool file, work its threats here, and write the treatment status back into the .tm7.

    In preparation
  2. Map a standard onto your development process

    Import a standard, build the secure-SDLC workflow, assign each requirement to an activity, and read what is left as a gap.

    In preparation
  3. Invite your team and get the TRA approved

    Roles, review, sign-off and release — the path from a draft assessment to a released version a product can stand on.

    In preparation
  4. Reuse one TRA across product variants

    When a single assessment may legitimately cover several products, and how to record the reasoning when it may not.

    In preparation

When a walkthrough does not answer it

Write to us — a walkthrough that leaves a question open is a walkthrough we need to fix, and we would rather hear it than not. The community forum is where users compare notes, and a facilitated workshop is the option when the question is about your product rather than about the tool.