Build a threat model for StudyBuddy's core system.
- Draw a data-flow diagram (in text) with external entities (students, TAs/instructors, university SSO, AI provider), processes (REST API, tutor module, moderation), data stores (MySQL, course-file index, logs) and data flows. Mark the trust boundaries.
- Identify at least eight threats — at least one per STRIDE category — each with: the element attacked, a concrete attack, likelihood (1–3), impact (1–3), risk (L × I), and a mitigation.
- Sort the threats by risk and choose the top three to address in the next Sprint; turn each into a testable security requirement (EARS) and a security test.
- List two assumptions your model depends on (e.g., "the SSO is secure").