The Threat Modeling Manifesto – Part 1 episode artwork

EPISODE · Nov 17, 2020 · 25 MIN

The Threat Modeling Manifesto – Part 1

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

What should threat modeling mean when practitioners use the term in very different ways? Part one of the Threat Modeling Manifesto documents a six-month collaboration among experienced practitioners trying to create a definition, values, and principles the community can support. The recording preserves real disagreements about people, design, privacy, tools, jargon, and how broad the practice should be. Contributors including Alyssa Miller, Fraser Scott, Brook Schoenfield, Matthew Coles, Chris Romeo, and Robert Hurlbut test individual words against years of teaching and consulting experience. Rather than presenting a polished result without context, the episode shows the difficult work of building consensus and deciding how a short public statement can remain precise without becoming inaccessible.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with the Threat Modeling Manifesto contributors:→ Threat Modeling Manifesto→ Chris Romeo on LinkedIn→ Robert Hurlbut on LinkedInMentioned in this episode:→ Threat Modeling Manifesto→ Zoe Braiterman→ Adam Shostack→ Jonathan Marcil→ Stephen de Vries and IriusRisk→ Irene Michlin→ Kim Wuyts→ Robert Hurlbut→ Brook Schoenfield→ Matthew Coles→ Chris Romeo→ Alyssa Miller→ Izar Tarandach→ Avi Douglen→ Marc French→ Agile ManifestoFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 Why the Threat Modeling Manifesto was created01:25 Beginning the definition debate02:57 Putting people at the center04:16 Defining the boundaries of threat modeling04:59 Alyssa Miller on security, privacy, and business06:38 Building a definition the community can support08:34 Fraser Scott on precise language09:39 Brook Schoenfield on models and experience12:09 Quality, buzz, and practitioner expectations14:03 Short and long definitions16:27 What counts as a threat modeling tool18:25 Separating values from principles20:35 Converging on the wording23:09 Reviewing the remaining disagreements25:04 How values become practice

Episode metadata supplied by the publisher feed · Published Nov 17, 2020

Embed this episode

What should threat modeling mean when practitioners use the term in very different ways? Part one of the Threat Modeling Manifesto documents a six-month collaboration among experienced practitioners trying to create a definition, values, and principles the community can support. The recording preserves real disagreements about people, design, privacy, tools, jargon, and how broad the practice should be. Contributors including Alyssa Miller, Fraser Scott, Brook Schoenfield, Matthew Coles, Chri...

Distinct summary based on available episode metadata or transcript content.

Ready to play

The Threat Modeling Manifesto – Part 1

0:00 25:19

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 25 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on November 17, 2020.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!