Irene Michlin -- We Are Not Making It Worse episode artwork

EPISODE · Feb 9, 2018 · 33 MIN

Irene Michlin -- We Are Not Making It Worse

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

When a team is already ten sprints into a product, stopping to threat model everything can sound impossible. Irene Michlin explains an incremental approach: examine the next change, keep the discussion bounded, and make sure new work does not make the system worse. Drawing on her experience as a developer and security practitioner, she describes how short exercises build confidence and how threat modeling improves testing and shared architectural understanding. Chris and Robert explore what to do about existing security debt, how to record threats in the team’s normal work tracker, and where security stories and acceptance criteria fit. Irene also discusses whiteboards, the Microsoft Threat Modeling Tool, and STRIDE, emphasizing a repeatable thinking habit that can keep pace with agile development.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Irene Michlin:→ Irene Michlin on LinkedInMentioned in this episode:→ Microsoft Threat Modeling ToolFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Incremental threat modeling with Irene Michlin01:21 Irene’s path from development into AppSec05:05 Security products still need product security06:41 The wider benefits of threat modeling09:04 Starting with the next sprint’s changes11:24 Handling existing security debt13:46 Teaching a lightweight modeling process17:21 Using a timer to build confidence18:28 Keeping threats in the team’s work tracker20:19 Security stories and acceptance criteria23:16 Defining done for security work24:24 Choosing tools for fast threat modeling27:06 Using STRIDE as a foundation29:07 Adding context-specific threats

Episode metadata supplied by the publisher feed · Published Feb 9, 2018

Embed this episode

When a team is already ten sprints into a product, stopping to threat model everything can sound impossible. Irene Michlin explains an incremental approach: examine the next change, keep the discussion bounded, and make sure new work does not make the system worse. Drawing on her experience as a developer and security practitioner, she describes how short exercises build confidence and how threat modeling improves testing and shared architectural understanding. Chris and Robert explore what t...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Irene Michlin -- We Are Not Making It Worse

0:00 33:02

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 33 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on February 9, 2018.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!