What is the main advantage of using threat modeling as part of QA rather than as a standalone security activity?
-
A
It reduces the need for penetration testing entirely
-
B
It aligns security test cases with identified threats before code is written
-
C
It satisfies all compliance requirements automatically
-
D
It replaces security architecture reviews