The Threat Modeling Manifesto – Part 2 episode artwork

EPISODE · Nov 24, 2020 · 24 MIN

The Threat Modeling Manifesto – Part 2

from The Application Security Podcast · host Chris Romeo and Robert Hurlbut

How did a group of experienced practitioners turn months of disagreement into a usable Threat Modeling Manifesto? Part two follows the contributors as they refine principles, test language, and decide what belongs in the final document. The discussion compares recipes with adaptable patterns, examines the gap between documentation and shared understanding, and confronts the difficulty of proving threat modeling’s return on investment. Contributors including Alyssa Miller, Irene Michlin, Fraser Scott, Chris Romeo, and Robert Hurlbut debate whether guidance is essential or optional and whether patterns and anti-patterns can make it more actionable. The episode ends with the final principles and a complete acknowledgement of the people who created the Manifesto.The Application Security Podcast is brought to you by Security Journey.About Security JourneySecurity Journey provides application security education for developers and everyone in the software development lifecycle.→ Learn more about Security JourneyConnect with the Threat Modeling Manifesto contributors:→ Threat Modeling Manifesto→ Chris Romeo on LinkedIn→ Robert Hurlbut on LinkedInMentioned in this episode:→ Threat Modeling Manifesto→ Zoe Braiterman→ Adam Shostack→ Jonathan Marcil→ Stephen de Vries and IriusRisk→ Irene Michlin→ Kim Wuyts→ Robert Hurlbut→ Brook Schoenfield→ Matthew Coles→ Chris Romeo→ Alyssa Miller→ Izar Tarandach→ Avi Douglen→ Marc French→ Agile ManifestoFollow the Application Security Podcast:➜ Home➜ X➜ LinkedIn➜ YouTube➜ Instagram➜ FacebookChapters:00:00 From debate to a finished Manifesto02:48 Recipes, patterns, and adaptable practice05:04 Documentation versus shared understanding08:14 The return on investment of threat modeling09:49 Structure and systematic analysis12:56 Refining the principles13:34 Alyssa Miller’s perspective14:43 Irene Michlin joins the debate16:12 Essential guidance versus optional advice17:55 Preserving the power of the principles19:28 Patterns and anti-patterns21:15 Helping teams become more effective22:42 Reading the final principles24:04 The Manifesto contributors

Episode metadata supplied by the publisher feed · Published Nov 24, 2020

Embed this episode

How did a group of experienced practitioners turn months of disagreement into a usable Threat Modeling Manifesto? Part two follows the contributors as they refine principles, test language, and decide what belongs in the final document. The discussion compares recipes with adaptable patterns, examines the gap between documentation and shared understanding, and confronts the difficulty of proving threat modeling’s return on investment. Contributors including Alyssa Miller, Irene Michlin, Frase...

Distinct summary based on available episode metadata or transcript content.

Ready to play

The Threat Modeling Manifesto – Part 2

0:00 24:50

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

How long is this episode of The Application Security Podcast?

This episode is 24 minutes long.

When was this The Application Security Podcast episode published?

This episode was published on November 24, 2020.

Can I download this The Application Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!