How to audit false positives
Question
What if I believe that an issue for the indicated model elements is not valid, that it is a false positive?
Answer
The following can be done, for example, in the Microsoft Threat Modeling Tool for circumstances where it is believed that a invalid issue has been identified, that it is a false positive:
- In the Threat Properties window, for the Status pulldown, select “Not Applicable”
- In the Threat Properties window, for the Justification, write “This threat is not valid. [rationale here] as per [document name] [document section].”
References
none