Threat Modeling With Good Questions and Without Checklists - Farshad Abasi - ASW #335 Image

Threat Modeling With Good Questions and Without Checklists - Farshad Abasi - ASW #335

17 June - 1 hour 8 mins
Podcast Series Security Weekly Podcast Network (Audio)

What makes a threat modeling process effective? Do you need a long list of threat actors? Do you need a long list of terms? What about a short list like STRIDE? Has an effective process ever come out of a list? Farshad Abasi joins our discussion as we explain why the answer to most of those questions is No and describe the kinds of approaches that are more conducive to useful threat models.

Resources:

https://www.eurekadevsecops.com/agile-devops-and-the-threat-modeling-disconnect-bridging-the-gap-with-developer-insights/ https://www.threatmodelingmanifesto.org https://kellyshortridge.com/blog/posts/security-decision-trees-with-graphviz/ In the news, learning from outage postmortems,...

1 hour 8 mins

Series Episodes

Recommended

Show name

Title

Sub title

Now Playing

The Pat Kenny Show

Live Now: 9AM - 12PM

Presenter logo
Brand

9AM

12AM

Now Playing

The Pat Kenny Show

The Pat Kenny Show

Of The Ball

1 hour left

Today Finished


Next Up

Default

Default

default

0 mins

No Account

Subscriptions to podcast series are only available to users with an account. Sign in or register to subscribe and access your subscriptions.

Register Sign in

Woops!

Error text.