EPISODE · Apr 6, 2018 · 32 MIN
Steven Wierckx -- The #OWASP Threat Modeling Project
from The Application Security Podcast · host Chris Romeo and Robert Hurlbut
Can a threat modeling community bring different methods together without forcing everyone into the same process? Steven Wierckx explains the goals of the OWASP Threat Modeling Project and the work that grew out of the security summit. He describes a vendor-neutral, methodology-neutral collection of knowledge organized around four questions: what are we building, what can go wrong, what will we do about it, and did we do enough? Chris and Robert explore how examples, reference models, and open discussion could help practitioners compare approaches and adapt them to agile development. Steven also explains the relationship between documentation and tools such as Threat Dragon. The episode closes with how working sessions and community contributions can turn shared experience into practical resources.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Steven Wierckx:→ Steven Wierckx on LinkedInMentioned in this episode:→ OWASP Threat Modeling Project→ OWASP Threat Dragon→ Open Security Summit 2018 archiveFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 The OWASP Threat Modeling Project01:11 Steven’s security origin story04:04 How the summit shaped the project07:42 What methodology-neutral threat modeling means10:46 The four common threat modeling questions12:30 Building a community of practitioners15:34 Example models and the project roadmap20:05 How documentation and Threat Dragon fit together24:15 Planning the Open Security Summit27:48 Turning working sessions into published resources30:28 How to participate in threat modeling
Embed this episode
What this episode covers
Can a threat modeling community bring different methods together without forcing everyone into the same process? Steven Wierckx explains the goals of the OWASP Threat Modeling Project and the work that grew out of the security summit. He describes a vendor-neutral, methodology-neutral collection of knowledge organized around four questions: what are we building, what can go wrong, what will we do about it, and did we do enough? Chris and Robert explore how examples, reference models, and open...
Ready to play
Steven Wierckx -- The #OWASP Threat Modeling Project
No transcript for this episode yet
Similar Episodes
No similar episodes found.
Similar Podcasts
No similar podcasts found.