High-Level Threat Modelling
A nice synapsis on how the ideas in the Threat Modelling book by Window Snyder et al. might be put to use in practice. (As in: Hey Microsoft, cool idea - but just how to you do it in real life?)
http://weblogs.asp.net/ptorr/archive/2005/02/08/368881.aspx
Not bad, but ends somewhat early.
- I always thought that other key benefits to do threat modelling are, that you could
a) show the morons that want to introduce insecurity later on in the project, what that will do to them easily and illustratively
b) have a readily available, nice residual risk piece for final sign-off