Ketil Stølen is Chief Scientist at SINTEF ICT, Oslo, Norway, where he leads the Group for Quality and Security Technology at the Department for Cooperative and Trusted Systems. Mass Soldal Lund is a researcher this group, specialising on risk analysis and thread modeling. Bjørnar Solhaug is a PhD student at the Department of Information Science and Media Studies, University of Bergen, Norway, and SINTEF ICT, working on formal languages for the specification of trust management policies.