threat-modeling.sgit.ai / papers / Scaling Supply Chain Security using Threat Modeling, Semantic Knowledge Graphs and Maps
Scaling Supply Chain Security using Threat Modeling, Semantic Knowledge Graphs and Maps
Shares the previous paper's spine and adds maps — specifically Wardley maps — as the visualisation layer for prioritising supply-chain risk once it is modelled as a graph.
What it argues
- The same mandatory-disclosure-to-graph-to-monitoring spine as the sibling paper, extended with a mapping layer for situational awareness.
- Where this site touches wardley-maps.sgit.ai: only as an application of the mapping technique to threat prioritisation, not as a second home for the technique itself — see the deconfliction table on /network/.
- This is the theoretical basis for the ThreatModCon vault's five Wardley walkthroughs, embedded on /eleven-layers/.
What checks it
This paper states a mechanism and a set of consequences. The ThreatModCon 2025 vault is the working proof at the scale this and the sibling papers argue for — not a demo built to illustrate the paper, but a published vault carrying real graph data (51 nodes, 179 threats across eleven linked layers). /validated/ is the sharper instance: a threat model checked, finding by finding, against the code it describes.