Threat modeling is a cybersecurity control or practice. It supports this objective: identifies trust boundaries, misuse cases, and likely attack paths before implementation. In practice, document the business and security objective, the system boundary, the owner and the evidence that will show the control is operating as intended.NIST Cybersecurity Framework 2.0: https://www.nist.gov/cyberframework