EPISODE · Aug 13, 2021 · 36 MIN
Mark Loveless -- Threat modeling in a DevSecOps environment.
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Threat modeling needs to fit the way developers work if it is going to survive a fast delivery cycle. Mark Loveless, also known as Simple Nomad, explains how GitLab adapted its approach for an asynchronous DevSecOps environment. He describes moving ownership toward the people building a project, introducing lightweight checkpoints, and making the process useful beyond engineering. The discussion explores a simplified version of PASTA, ordinary language instead of security jargon, and documentation that lives in familiar tools. Mark shares adoption tactics and examples of teams identifying risks for themselves. Throughout, he argues that security specialists should provide a usable framework and practical support while helping everyone develop the habit of asking what could go wrong.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Mark Loveless:→ Mark Loveless’s websiteMentioned in this episode:→ Mark’s GitLab threat modeling article→ PASTA threat modeling→ Mermaid diagramsFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Threat modeling at GitLab with Mark Loveless01:44 Mark’s security origin story05:04 The GitLab threat modeling article series06:11 Adapting threat modeling to DevSecOps08:58 Starting threat modeling without disrupting flow10:33 Where modeling fits in developer workflows13:09 Extending threat modeling beyond engineering14:56 Encouraging teams to participate19:03 Choosing and simplifying PASTA23:19 Using plain language instead of jargon25:12 Writing models with familiar tools26:55 Adoption stories and signs of success33:18 Key takeaways and getting started
Embed this episode
What this episode covers
Threat modeling needs to fit the way developers work if it is going to survive a fast delivery cycle. Mark Loveless, also known as Simple Nomad, explains how GitLab adapted its approach for an asynchronous DevSecOps environment. He describes moving ownership toward the people building a project, introducing lightweight checkpoints, and making the process useful beyond engineering. The discussion explores a simplified version of PASTA, ordinary language instead of security jargon, and document...
Ready to play
Mark Loveless -- Threat modeling in a DevSecOps environment.
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.