Threat-First Governance 101 — Threat Modelling and Control Ownership on SAP Analytics Engagements
As of 2026-10-10
Threat-first governance is a three-discipline governance practice (threat-first × ownership × secure-by-default) every SAP analytics consultant carries across every engagement. This module is the 60-minute workshop that lets a Y3-Y8 consultant operate it on day 1 of a new mission. By the end the consultant has drafted (a) a threat-tree per critical data flow, (b) an ownership map for every identified control, (c) the override-vs-default ledger for the engagement, and (d) the tagged risk register the client's auditor will read in week 12.
What you will learn
- Operate threat-first governance on day 1 of a new SAP analytics engagement.
- Produce a 4-step threat tree per critical data flow.
- Convert threat-tree findings into an ownership map with bus-factor flags.
- Walk the secure-by-default pattern library and produce the override ledger.
- Consolidate into a tagged risk register for the client's auditor.
60-minute workshop structure
0-10 min · Frame Why threat-first governance exists, what the three disciplines mean, how the [discipline · control · severity] tag works.
10-25 min · Threat-tree practice Pick one real data flow from the engagement (ECC → Datasphere → SAC story is the default exercise). Walk the 4 steps: asset inventory · trust boundaries · STRIDE-light per boundary · blast-radius scoring. Produce the 1-page output.
25-40 min · Ownership map For each control identified in the threat tree, name: owner (human, not alias) · runbook link · bus factor · RTO. Convert the threat tree into an ownership document. Bus-factor 1 entries get a 'fix before go-live' flag.
40-55 min · Secure-by-default override audit Walk the secure-by-default pattern library. For each pattern, decide: keep default, or document override + owner + reason. Produce the override ledger. Any override without owner = blocker.
55-60 min · governance risk register Merge threat-tree findings + ownership-map gaps + override ledger into ONE governance risk register with [discipline · <control> · <severity>] tags per line. This is the document the client's auditor will read in week 12 and the document the consultant hands off when rolling onto the next engagement.
Prerequisites
- Y3+ SAP analytics consulting experience
- Read the platform charter + a written playbook
Outcomes
- By end of workshop: 1 threat tree · 1 ownership map · 1 override ledger · 1 risk register.
- Concrete artefacts the auditor reads.
- Apply the module's rule: if data classification = restricted (PII identifying natural persons), then blast radius must be < 100 users; threat tree must be P0 on any RLS bypass.
- Recognize and avoid this anti-pattern: Skipping the threat tree because the architecture 'looks fine' — the auditor walks the data flow, not the design doc.
Full module available to members. The full module adds: the decision framework · the end-to-end scenario walkthrough · the KPI scorecard · the anti-patterns · the code blocks · the knowledge check · the diagrams.