Stephen de Vries -- Threat Modeling with a bit of #Startup episode artwork

EPISODE · Aug 20, 2018 · 22 MIN

Stephen de Vries -- Threat Modeling with a bit of #Startup

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

What developers need from a threat model is often a clear set of requirements they can implement. Stephen de Vries explains how that perspective shaped IriusRisk and his move from security consulting into building a product company. He and Chris discuss reusable threats and countermeasures, the role of OWASP ASVS, and the need to translate guidance into instructions that make sense in an issue tracker. They also examine why spreadsheets and separate security systems create friction, and how existing testing and design habits can provide a bridge into security. Stephen’s startup experience frames a broader conversation about making threat modeling repeatable: reuse what is known, focus human attention on the difficult parts, and meet developers inside their normal workflow.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Stephen de Vries:→ Stephen de Vries on LinkedIn→ IriusRiskMentioned in this episode:→ OWASP Application Security Verification Standard→ OWASP Proactive Controls→ OWASP Web Security Testing GuideFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Threat modeling and startup lessons with Stephen de Vries00:34 Stephen’s development and security background05:01 Starting a security product company06:35 From building a product to building a company07:48 Threat modeling as a route to security requirements10:41 Reusing common threats and countermeasures12:00 Connecting requirements management and threat modeling13:43 Turning ASVS into actionable developer guidance14:16 Meeting developers in their existing tools15:33 Removing spreadsheet and email friction17:00 Building on testing and design habits18:41 Connecting everyday risk thinking to security20:06 Behavior-driven testing and useful OWASP resources

Episode metadata supplied by the publisher feed · Published Aug 20, 2018

Embed this episode

What developers need from a threat model is often a clear set of requirements they can implement. Stephen de Vries explains how that perspective shaped IriusRisk and his move from security consulting into building a product company. He and Chris discuss reusable threats and countermeasures, the role of OWASP ASVS, and the need to translate guidance into instructions that make sense in an issue tracker. They also examine why spreadsheets and separate security systems create friction, and how e...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Stephen de Vries -- Threat Modeling with a bit of #Startup

0:00 22:14

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 22 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on August 20, 2018.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!