> For the complete documentation index, see [llms.txt](https://framework.aic.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://framework.aic.io/security-vetting-and-technical-assurance-playbook/templates-and-checklists/threat-model-template.md).

# Threat Model Template

### Purpose

This template provides a structured artefact for project teams to copy into their delivery workspace, Statement of Work pack, assurance pack or customer governance process.

### Template

| Field                 | Entry                                                                                       |
| --------------------- | ------------------------------------------------------------------------------------------- |
| Project               | \[Project name]                                                                             |
| Customer              | \[Customer name]                                                                            |
| Statement of Work     | \[SoW reference]                                                                            |
| Security owner        | \[Name / role]                                                                              |
| Technical owner       | \[Name / role]                                                                              |
| Data owner            | \[Name / role]                                                                              |
| Supplier owner        | \[Name / role]                                                                              |
| Classification        | \[OFFICIAL / OFFICIAL-SENSITIVE / SECRET / TOP SECRET / customer classification]            |
| Applicable frameworks | \[Secure by Design / CSM / Def Stan / CAF / ISO / Cyber Essentials / JSP / customer policy] |
| Scope                 | \[Systems, services, data, users, suppliers, environments]                                  |
| Out of scope          | \[Explicit exclusions]                                                                      |
| Assumptions           | \[Assumptions]                                                                              |
| Dependencies          | \[Dependencies]                                                                             |
| Risks                 | \[Risks]                                                                                    |
| Evidence location     | \[Repository / folder / assurance tool]                                                     |

### Control Record

| ID      | Requirement    | Control    | Owner    | Evidence    | Status    | Review date |
| ------- | -------------- | ---------- | -------- | ----------- | --------- | ----------- |
| SEC-001 | \[Requirement] | \[Control] | \[Owner] | \[Evidence] | \[Status] | \[Date]     |

### Approval Record

| Decision    | Approver       | Date    | Evidence |
| ----------- | -------------- | ------- | -------- |
| \[Decision] | \[Name / role] | \[Date] | \[Link]  |

### Completion Checklist

* [ ] Scope confirmed
* [ ] Owner confirmed
* [ ] Requirements captured
* [ ] Controls mapped
* [ ] Evidence attached
* [ ] Supplier impact checked
* [ ] Risk reviewed
* [ ] Approval recorded
* [ ] Next review scheduled
