Many people say that threat modeling is exponentially expensive:
Can the entire system be threat modeled?If not, how would you objectively decide which parts of the system to model?