Review a change or system for concrete threats involving authentication, authorization, data, injection, dependencies, and access.