Steven Wierckx -- The #OWASP Threat Modeling Project episode artwork

EPISODE · Apr 6, 2018 · 32 MIN

Steven Wierckx -- The #OWASP Threat Modeling Project

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

Can a threat modeling community bring different methods together without forcing everyone into the same process? Steven Wierckx explains the goals of the OWASP Threat Modeling Project and the work that grew out of the security summit. He describes a vendor-neutral, methodology-neutral collection of knowledge organized around four questions: what are we building, what can go wrong, what will we do about it, and did we do enough? Chris and Robert explore how examples, reference models, and open discussion could help practitioners compare approaches and adapt them to agile development. Steven also explains the relationship between documentation and tools such as Threat Dragon. The episode closes with how working sessions and community contributions can turn shared experience into practical resources.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with Steven Wierckx:→ Steven Wierckx on LinkedInMentioned in this episode:→ OWASP Threat Modeling Project→ OWASP Threat Dragon→ Open Security Summit 2018 archiveFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 The OWASP Threat Modeling Project01:11 Steven’s security origin story04:04 How the summit shaped the project07:42 What methodology-neutral threat modeling means10:46 The four common threat modeling questions12:30 Building a community of practitioners15:34 Example models and the project roadmap20:05 How documentation and Threat Dragon fit together24:15 Planning the Open Security Summit27:48 Turning working sessions into published resources30:28 How to participate in threat modeling

Episode metadata supplied by the publisher feed · Published Apr 6, 2018

Embed this episode

Can a threat modeling community bring different methods together without forcing everyone into the same process? Steven Wierckx explains the goals of the OWASP Threat Modeling Project and the work that grew out of the security summit. He describes a vendor-neutral, methodology-neutral collection of knowledge organized around four questions: what are we building, what can go wrong, what will we do about it, and did we do enough? Chris and Robert explore how examples, reference models, and open...

Distinct summary based on available episode metadata or transcript content.

Ready to play

Steven Wierckx -- The #OWASP Threat Modeling Project

0:00 32:30

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 32 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on April 6, 2018.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!