Security Context Canvas
The core artefact of week 1. In a single lesson block, teams bring their case together on one sheet: context, stakeholders, behaviour, assets, abuse cases and the first design principles. The canvas then stays — it grows week by week into the secure-by-design dossier in week 4.
01 The canvas
Every field is the harvest of exactly one lesson block from week 1 — so the canvas never asks for anything that has not been taught yet. Click the image for full resolution.

02 How to read it
What are we talking about, why does it matter, and which of availability, integrity or confidentiality weighs heaviest here?
Stakeholders and their conflicting interests, what users actually do on a busy day, and who would stand to gain from misuse.
Numbered assets, at least three abuse cases that each point back to an asset number, and the design principles that follow from them.
Two strips along the bottom keep the canvas alive: assumptions & open questions — what do we not know yet? — and take into week 2, the risk the team currently finds sharpest.
03 It keeps growing
Not one sheet that gets ever fuller, but one backbone with layers. The link is the asset numbering: what is called A1 in week 1 stays A1 for the rest of the minor.
- Week 1Security Context Canvascontext, assets, abuse cases
- Week 2Risk profile layerlikelihood × impact, first controls
- Week 3Governance layerlaw, standards, roles, supply chain
- Week 4Secure-by-design dossierrequirements, architecture, lifecycle
04 Want to weigh in?
The canvas is still a proposal — feedback on the fields, the order or the case is welcome. Use the feedback button in the corner, or get in touch. contact