What is the difference between an asset-based and a threat-based project prioritisation approach?
In principle, very little. If both approaches include a comprehensive set of criteria, they should come up with more or less the same priorities. We prefer to start by identifying the assets because we think it helps shape the mind set of users, and it helps with communication. In practice, the threat-based approached with which we are familiar are not sufficiently comprehensive, often omitting key factors such as technical feasibility and practice change/adoptability from the assessment.