Skip to main content

Turn Requirements into a Project

A threat model nobody acts on is a document. This guide turns it into work: the platform creates a project from the requirements generated for each part of your architecture, so your team can assign, track, and evidence each one.

Objective

By the end of this guide, you will have:

  • Created a project from the latest version of a threat model.
  • Located the security requirements and activities generated for each architecture item.
  • Understood how to move activities through their statuses and attach evidence.

Prerequisites

  • A threat modeling artifact with at least one version. See Create a Threat Model.
  • Permission to create projects in your company.

Steps

Step 1 – Create the project

  1. Open the artifact in Threat Modeling.
  2. Click Create project from latest version.
  3. Enter the Project Name.
  4. Select the Start date and End date from the calendar.
  5. Fill in the Goal and the Scope and limitations.
  6. Review Requirement Templates and remove any architecture item you do not want to work on now.
  7. Click Create a new project.

Step 1: Project form opened from the artifact, with Project Type set to Threat Modeling and one requirement template per architecture item.

Step 1: Create a project from a threat model version

The platform pre-fills Project Type as Threat Modeling and lists one requirement template per architecture item found in the model.

FieldRequired
Project NameYes
Start date and End dateYes
GoalYes
Scope and limitationsYes
Assets, Tags, Assigned users, Teams, AttachmentsNo

Step 2 – Open the generated requirements

  1. Open the project from Projects.
  2. Select the Requirements tab.
  3. Click a requirement group to expand it.

Step 2: Requirements tab listing one group per architecture item, with a group expanded to show its activities.

Step 2: Project requirements generated from the threat model

Each group corresponds to one part of your architecture and shows how many activities it contains. Expanding it reveals the activities, each with a name, status, assigned users, last update, and history with attachments.

Step 3 – Work through the activities

For each activity:

  1. Confirm whether it applies to your system.
  2. Assign it to whoever will do the work.
  3. Move it to Running when work starts.
  4. When finished, move it to Done and attach the evidence.
  5. If it does not apply, mark it Not Applicable and record the justification.
StatusUse it when
To doNot started. Every activity begins here.
RunningWork is in progress.
DoneImplemented, with evidence attached.
Not ApplicableDoes not apply to your system. Always justify.
Not AccordingReviewed and found not to meet the requirement.
tip

Attach evidence while the work is fresh — a screenshot, a configuration excerpt, or a link to a pull request. It is what turns "we handled it" into something you can prove later.

Validation

CheckExpected result
After creating the projectYou are redirected to Projects and the new project is listed.
Project DetailsProject Type is Threat Modeling.
Requirements tabShows one group per architecture item from the model.
Expanding a groupLists its activities, each starting at To do.

Troubleshooting

ProblemWhat to do
This field is required on submitStart date, End date, Goal, and Scope and limitations are mandatory. Dates only accept values from the calendar.
The Requirements tab is emptyThe version used had no requirement groups. Generate a new version and create the project again.
A requirement group is missingIt was removed from Requirement Templates during creation. Add it with Create Requirement, or create a new project from the artifact.
The requirements do not reflect the current architectureThe project was created from an older version. Generate a new version and create a project from it.

Next steps

Support

Should you have any questions or require assistance while using the Conviso Platform, feel free to reach out to our dedicated support team.

Contribute to the Docs

Found something outdated or missing? Help us improve the documentation with a quick suggestion or edit.

How to contribute

Resources

By exploring our content, you'll find resources that will enhance your understanding of the importance of a Security Application Program.

Conviso Blog: Explore our blog, which offers a collection of articles and posts covering a wide range of AppSec topics. The content on the blog is primarily in English.

Conviso's YouTube Channel: Access a wealth of informative videos covering various topics related to AppSec. Please note that the content is primarily in Portuguese.