This is very interesting analysis. Thanks for this :) I wonder if its possible to break down the story in more than one way mentioned here. For instance, the products-shop story, can be broken down by business rules and by workflow steps and they both look useful. What are your experiences with this?
CTO of we45 (An AppSec Company), DevSecOps Greasemonkey, Passionate Security Technologist and Creator