This is a report that I will put in front of the security architect to
capture (a) the most significant Threats identified (whether mitigated
or not), and a detailed list of each Threat that was identified in the
model.
Unfortunately, I have at least two major bugs in this report:
(a) The "top ten" threats table enumerates all threats, not just the
top ten - which is semi-deliberate, as I haven't been able to figure
out how to get XSL or XPath code to give me just the first ten in my
sorted list.
(b) I cannot figure out how to populate the tables in (2).
You're welcome to try this yourself, and to leverage the work I've
done so far. If anyone has any idea how to fix the bug(s) that my
report still has, please let me know and/or just upload a fixed
version of the file. Any contributions are welcome.
Have a look in http://groups.google.com/group/microsoft-threat-modeling-tools/files
for the "Threat Enumeration Summary.xslt" file.