EPISODE · Jul 9, 2019 · 1 MIN
Adam Shostack – Threat Modeling – 5 Minute AppSec
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Why threat model when AppSec teams already have scanners, checklists, and testing? Adam Shostack argues that threat modeling is what makes those activities structured, systematic, and comprehensive instead of a collection of guesses. In this rapid 5 Minute AppSec, he explains how asking what you are building and what can go wrong focuses attention on the right parts of a system. Approaches such as STRIDE, attack trees, and kill chains help teams examine each element methodically, then use the results to guide the rest of the security program. Skip that step, Adam warns, and you are shooting in the dark. Stay through the end for a candid recording outtake.Connect with Adam Shostack:→ Adam Shostack on LinkedIn→ Shostack + AssociatesMentioned in this episode:→ Adam Shostack→ Attack Trees (Schneier)→ Cyber Kill Chain (Lockheed Martin)Follow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Why threat model?00:10 Structured, systematic, and comprehensive security01:07 The promised full interview01:33 A candid recording outtake
Embed this episode
What this episode covers
Why threat model when AppSec teams already have scanners, checklists, and testing? Adam Shostack argues that threat modeling is what makes those activities structured, systematic, and comprehensive instead of a collection of guesses. In this rapid 5 Minute AppSec, he explains how asking what you are building and what can go wrong focuses attention on the right parts of a system. Approaches such as STRIDE, attack trees, and kill chains help teams examine each element methodically, then use the...
Ready to play
Adam Shostack – Threat Modeling – 5 Minute AppSec
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.