@@ -32,26 +32,25 @@ during the software development life cycle.
3232
3333#### What is Cornucopia?
3434
35- Cornucopia provides a [ set of cards] [ cornucopia-cards ] designed to gamify threat modeling activities.
36- This is designed so that agile development teams can identify weaknesses in web applications
37- and then record remediations or requirements.
35+ Cornucopia provides a [ set of cards] [ cornucopia-cards ] designed to gamify threat modeling activities,
36+ helping agile development teams to identify weaknesses in applications and then record remediations or requirements.
3837
3938There are three versions of the Cornucopia deck of threat modeling cards:
4039
4140* Website App Edition
4241* Mobile App Edition
4342* Enterprise App Edition
4443
45- The decks come with different suits according to the application, and always contain a 'Cornucopia' suit.
44+ The decks come with several suits according to the application, and always contain an overall 'Cornucopia' suit.
4645
47- There is no one 'right' way to play Cornucopia but there is a suggested [ set of rules ] [ cornucopia-play ]
48- to start the game off.
49- Cornucopia provides a [ score sheet] [ cornucopia-score ] to help keep track of the game session and to record outcomes.
46+ Cornucopia can be played in many different ways, there is no one way,
47+ and there is a suggested [ set of rules ] [ cornucopia-play ] to start the game off.
48+ Cornucopia provides a [ score sheet] [ cornucopia-score ] to can help keep track of the game session and to record outcomes.
5049
5150#### Website App Edition
5251
5352Each card in the Website App deck describes a common error or anti-pattern that allows systems to be vulnerable to attack.
54- Vulnerabilities are arranged in domains as five key suits, with the additional Cornucopia suit ranging across domains:
53+ Vulnerabilities are arranged in domains as five suits with the additional Cornucopia suit ranging across these domains:
5554
5655* Data Validation and Encoding
5756* Authentication
@@ -82,7 +81,7 @@ with Cornucopia cross domain:
8281* Cryptography
8382* Cornucopia
8483
85- To provide context the Cornucopia Mobile App cards reference other projects:
84+ For context the Cornucopia Mobile App cards reference these other projects:
8685
8786* OWASP Mobile Application Security Verification Standard ([ MASVS] [ masvs ] )
8887* OWASP Mobile Application Security Testing Guide ([ MASTG] [ mastg ] )
@@ -92,7 +91,8 @@ To provide context the Cornucopia Mobile App cards reference other projects:
9291#### Ecommerce Website Edition
9392
9493This is the original Cornucopia deck and has the same domains/suits, including the Cornucopia cross domain suit,
95- as the Website App Edition. Some of the vulnerabilities are specific to Ecommerce, and it references the same projects.
94+ as the Website App Edition. Some of the vulnerabilities are specific to Ecommerce,
95+ but it references the same projects as the website edition.
9696
9797#### Why use it?
9898
0 commit comments