How to audit false positives

Question

What if I believe that an issue for the indicated model elements is not valid, that it is a false positive?

Answer

The following can be done, for example, in the Microsoft Threat Modeling Tool for circumstances where it is believed that a invalid issue has been identified, that it is a false positive:

  • In the Threat Properties window, for the Status pulldown, select “Not Applicable”
  • In the Threat Properties window, for the Justification, write “This threat is not valid. [rationale here] as per [document name] [document section].”

References

none