Did you know that ISO27001 requires you to do threat modeling? A 8.27 Requires you to "regularly update threat models to reflect changes in the system and external threat landscape." see: www.isms.online/iso-27001/ch... Why not try out threat modeling at copi.owasp.org#appsec #cybersec #owasp
Ľuboš Moščovič
in reply to Johan Sydseter • • •What about big fat NO?
Annex A is NOT mandatory.