Skip to content

Commit 888a99f

Browse files
committed
reword cornucopia
1 parent 7857233 commit 888a99f

File tree

2 files changed

+11
-11
lines changed

2 files changed

+11
-11
lines changed

_data/draft.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ docs:
44
- title: '1. Introduction'
55
url: introduction
66

7-
- title: '*2. Foundations*'
7+
- title: '2. Foundations'
88
url: foundations
99

1010
- title: '2.1 Security fundamentals'

draft/06-design/01-threat-modeling/04-cornucopia.md

Lines changed: 10 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -32,26 +32,25 @@ during the software development life cycle.
3232

3333
#### What is Cornucopia?
3434

35-
Cornucopia provides a [set of cards][cornucopia-cards] designed to gamify threat modeling activities.
36-
This is designed so that agile development teams can identify weaknesses in web applications
37-
and then record remediations or requirements.
35+
Cornucopia provides a [set of cards][cornucopia-cards] designed to gamify threat modeling activities,
36+
helping agile development teams to identify weaknesses in applications and then record remediations or requirements.
3837

3938
There are three versions of the Cornucopia deck of threat modeling cards:
4039

4140
* Website App Edition
4241
* Mobile App Edition
4342
* Enterprise App Edition
4443

45-
The decks come with different suits according to the application, and always contain a 'Cornucopia' suit.
44+
The decks come with several suits according to the application, and always contain an overall 'Cornucopia' suit.
4645

47-
There is no one 'right' way to play Cornucopia but there is a suggested [set of rules][cornucopia-play]
48-
to start the game off.
49-
Cornucopia provides a [score sheet][cornucopia-score] to help keep track of the game session and to record outcomes.
46+
Cornucopia can be played in many different ways, there is no one way,
47+
and there is a suggested [set of rules][cornucopia-play] to start the game off.
48+
Cornucopia provides a [score sheet][cornucopia-score] to can help keep track of the game session and to record outcomes.
5049

5150
#### Website App Edition
5251

5352
Each card in the Website App deck describes a common error or anti-pattern that allows systems to be vulnerable to attack.
54-
Vulnerabilities are arranged in domains as five key suits, with the additional Cornucopia suit ranging across domains:
53+
Vulnerabilities are arranged in domains as five suits with the additional Cornucopia suit ranging across these domains:
5554

5655
* Data Validation and Encoding
5756
* Authentication
@@ -82,7 +81,7 @@ with Cornucopia cross domain:
8281
* Cryptography
8382
* Cornucopia
8483

85-
To provide context the Cornucopia Mobile App cards reference other projects:
84+
For context the Cornucopia Mobile App cards reference these other projects:
8685

8786
* OWASP Mobile Application Security Verification Standard ([MASVS][masvs])
8887
* OWASP Mobile Application Security Testing Guide ([MASTG][mastg])
@@ -92,7 +91,8 @@ To provide context the Cornucopia Mobile App cards reference other projects:
9291
#### Ecommerce Website Edition
9392

9493
This is the original Cornucopia deck and has the same domains/suits, including the Cornucopia cross domain suit,
95-
as the Website App Edition. Some of the vulnerabilities are specific to Ecommerce, and it references the same projects.
94+
as the Website App Edition. Some of the vulnerabilities are specific to Ecommerce,
95+
but it references the same projects as the website edition.
9696

9797
#### Why use it?
9898

0 commit comments

Comments
 (0)