Adam Shostack – Threat Modeling – 5 Minute AppSec episode artwork

EPISODE · Jul 9, 2019 · 1 MIN

Adam Shostack – Threat Modeling – 5 Minute AppSec

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Why threat model when AppSec teams already have scanners, checklists, and testing? Adam Shostack argues that threat modeling is what makes those activities structured, systematic, and comprehensive instead of a collection of guesses. In this rapid 5 Minute AppSec, he explains how asking what you are building and what can go wrong focuses attention on the right parts of a system. Approaches such as STRIDE, attack trees, and kill chains help teams examine each element methodically, then use the results to guide the rest of the security program. Skip that step, Adam warns, and you are shooting in the dark. Stay through the end for a candid recording outtake.Connect with Adam Shostack:→ Adam Shostack on LinkedIn→ Shostack + AssociatesMentioned in this episode:→ Adam Shostack→ Attack Trees (Schneier)→ Cyber Kill Chain (Lockheed Martin)Follow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Why threat model?00:10 Structured, systematic, and comprehensive security01:07 The promised full interview01:33 A candid recording outtake

Episode metadata supplied by the publisher feed · Published Jul 9, 2019

Embed this episode

Why threat model when AppSec teams already have scanners, checklists, and testing? Adam Shostack argues that threat modeling is what makes those activities structured, systematic, and comprehensive instead of a collection of guesses. In this rapid 5 Minute AppSec, he explains how asking what you are building and what can go wrong focuses attention on the right parts of a system. Approaches such as STRIDE, attack trees, and kill chains help teams examine each element methodically, then use the...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Adam Shostack – Threat Modeling – 5 Minute AppSec

0:00 1:55

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 1 minute long.

When was this The Application Security Podcast episode published?

This episode was published on July 9, 2019.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!