threat-modeling.sgit.ai / papers / Scaling Supply Chain Security using Threat Modeling, Semantic Knowledge Graphs and Maps

Scaling Supply Chain Security using Threat Modeling, Semantic Knowledge Graphs and Maps

Shares the previous paper's spine and adds maps — specifically Wardley maps — as the visualisation layer for prioritising supply-chain risk once it is modelled as a graph.

Published
2025-05-30, docs.diniscruz.ai
Role
the domain case, plus maps
Co-authorship
Several of these papers credit “Dinis Cruz and ChatGPT Deep Research” in their front matter — kept visible rather than smoothed away, per this site's attribution rule
Source
https://docs.diniscruz.ai/docs/2025/05/30/scaling-supply-chain-security-using-threat-modeling-semantic-knowledge-graphs-and-maps.md — the paper itself, on docs.diniscruz.ai. This page summarises; it does not reproduce.

What it argues

What checks it

This paper states a mechanism and a set of consequences. The ThreatModCon 2025 vault is the working proof at the scale this and the sibling papers argue for — not a demo built to illustrate the paper, but a published vault carrying real graph data (51 nodes, 179 threats across eleven linked layers). /validated/ is the sharper instance: a threat model checked, finding by finding, against the code it describes.