The Threat Modeling Podcast

A Comprehensive Threat Modeling Strategy


Listen Later

The AppSec community agrees that threat modeling is essential, but many struggle to implement it effectively. Using insight from the LinkedIn community, Chris lays out a comprehensive Threat Modeling strategy to guide AppSec teams to success in this critical discipline.

Before starting, consider the organization's culture, tech debt, and current risk posture. Threat modeling will not be successful in an organization that doesn't prioritize security!

Tie threat modeling to the success of the business. See it as an enabler for the company, and define its success metrics clearly.

Integrate threat modeling into the development process in an agile and incremental manner. It's not about where you start but where you end up. It's essential to begin with critical applications and expand the scope over time.

Keep the Threat Model Up to Date. Threat modeling is a continuous process that adapts to new threats and system changes.

Make threat modeling holistic and straightforward. Start after the high-level design phase, and revisit the model continuously throughout a product's lifecycle.

Concentrate on domain-specific problems, which threat modeling is good at identifying. However, when identifying domain-agnostic issues, use automated approaches.

Special Thanks to the following individuals who provided feedback for this episode: Iswarya Subramanian Balachandar, Kuldeep Kumar, Abdoulkader (Abdo) Dirieh, Rob van der Veer, and Tony Turner.

Welcome to Smart Threat Modeling. Devici makes threat modeling simple, actionable, and scalable. Identify and deal with threats faster than ever. Build three free models and collaborate with up to ten people in our Free Forever plan. Get started at devici.com and threat model for free! Smart threat modeling for development teams.

...more
View all episodesView all episodes
Download on the App Store

The Threat Modeling PodcastBy Chris Romeo

  • 5
  • 5
  • 5
  • 5
  • 5

5

2 ratings


More shows like The Threat Modeling Podcast

View all
Security Now (Audio) by TWiT

Security Now (Audio)

1,963 Listeners

Risky Business by Patrick Gray

Risky Business

361 Listeners

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast) by Johannes B. Ullrich

SANS Internet Stormcenter Daily Cyber Security Podcast (Stormcast)

630 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,012 Listeners

The Application Security Podcast by Chris Romeo and Robert Hurlbut

The Application Security Podcast

36 Listeners

Malicious Life by Malicious Life

Malicious Life

924 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

7,822 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

163 Listeners

Hacking Humans by N2K Networks

Hacking Humans

312 Listeners

Practical AI by Practical AI LLC

Practical AI

189 Listeners

Cyber Work by Infosec

Cyber Work

101 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

118 Listeners

CISO Tradecraft® by CISO Tradecraft®

CISO Tradecraft®

48 Listeners

Risky Bulletin by risky.biz

Risky Bulletin

33 Listeners

CISSP Cyber Training Podcast - CISSP Training Program by Shon Gerber, vCISO, CISSP, Cybersecurity Consultant and Entrepreneur

CISSP Cyber Training Podcast - CISSP Training Program

26 Listeners