Abhay Bhargav -- Threat Modeling as Code episode artwork

EPISODE · Oct 23, 2018 · 28 MIN

Abhay Bhargav -- Threat Modeling as Code

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

A threat model that lives in an old document rarely keeps pace with the code it describes. Abhay Bhargav explains how threat modeling as code can connect user stories, abuse cases, threat scenarios, and specific controls inside an evolving development process. He describes choosing YAML as a familiar format, compares that approach with behavior-driven specifications, and shows how the result can help both engineering teams and security testers. The conversation introduces Threat Playbook and explores turning concrete mitigations into an attack model and useful testing direction. Abhay also discusses the challenge of automating tools with different interfaces, including ZAP and nodejsscan. The episode makes the case for keeping threat information actionable, versionable, and close to the people building the application.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Abhay Bhargav:→ Abhay Bhargav on LinkedIn→ we45Mentioned in this episode:→ Threat Playbook→ ZAP→ nodejsscanFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Threat modeling as code with Abhay Bhargav01:51 Early work in PCI and security03:37 Why traditional threat models become stale06:48 From user stories to abuse cases and threats08:32 Integrating the model into development09:16 YAML specifications and alternative approaches11:23 Benefits for DevOps and security teams14:13 Attack models and specific mitigations17:26 Introducing Threat Playbook20:40 The challenge of automated security pipelines22:54 Python and tool choices23:26 ZAP, nodejsscan, and npm audit26:37 Sharing the workshop materials

Episode metadata supplied by the publisher feed · Published Oct 23, 2018

Embed this episode

A threat model that lives in an old document rarely keeps pace with the code it describes. Abhay Bhargav explains how threat modeling as code can connect user stories, abuse cases, threat scenarios, and specific controls inside an evolving development process. He describes choosing YAML as a familiar format, compares that approach with behavior-driven specifications, and shows how the result can help both engineering teams and security testers. The conversation introduces Threat Playbook and ...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Abhay Bhargav -- Threat Modeling as Code

0:00 28:05

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 28 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on October 23, 2018.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!