Business and System Asset UML Class Diagram

How to Use This Web Page

  1. Explore the UML Class Diagrams: hover over separate blocks/classes and click on the element that you are interested in. For example - "Input data", this will lead you to the page with information about the business asset and threats, which target the business asset.
  2. Review the Business Asset Definitions: by selecting a system asset like "ML system input/API", you will get to the page with definition of the system asset and involved business assets.
  3. Examine Threat–Asset Relationships: by selecting a business asset, a diagram and a list with threats will be presented. By selecting a threat on the diagram, you will get to the page with the threat definitions.
  4. Check the BPMN Process Flows: there are 3 additional BPMN diagrams, which can be selected from the top navigation bar, depicting separate processes related to the model.
  5. Match Threats to Security Requirements: the pages for threats provide the related security requirement and security controls, which can help you to mitigate the threat.
  6. Combine with Your Organizational Context: apply the information from the asset and threat pages to your own ML/LLM system's context. Identify which assets exist in your environment, note the relevant threats, and consult the associated security requirements and controls to plan development or improvement of the present defenses.