
Sign up to save your podcasts
Or


Send us Fan Mail
Brett Crawley discusses the Elevation of Privilege (EoP) card game, a powerful tool for threat modeling in software development. The discussion explores recent extensions to the game including privacy-focused suits and TRIM (Transfer, Retention/Removal, Inference, Minimization) categories. Crawley emphasizes that threat modeling shouldn't end with the game but should be an ongoing process throughout an application's lifecycle, ideally starting before implementation. He also shares insights from his book, which provides detailed examples and guidance for teams new to threat modeling using EoP.
You can find Brett on X @brettcrawley
Brett’s book:
Threat Modeling Gameplay with EoP: A reference manual for spotting threats in software architecture
Book recommendation:
Conscious Business by Fred Kofman
FOLLOW OUR SOCIAL MEDIA:
➜Twitter: @AppSecPodcast
➜LinkedIn: The Application Security Podcast
➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast
Thanks for Listening!
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
By Chris Romeo and Robert Hurlbut5
3636 ratings
Send us Fan Mail
Brett Crawley discusses the Elevation of Privilege (EoP) card game, a powerful tool for threat modeling in software development. The discussion explores recent extensions to the game including privacy-focused suits and TRIM (Transfer, Retention/Removal, Inference, Minimization) categories. Crawley emphasizes that threat modeling shouldn't end with the game but should be an ongoing process throughout an application's lifecycle, ideally starting before implementation. He also shares insights from his book, which provides detailed examples and guidance for teams new to threat modeling using EoP.
You can find Brett on X @brettcrawley
Brett’s book:
Threat Modeling Gameplay with EoP: A reference manual for spotting threats in software architecture
Book recommendation:
Conscious Business by Fred Kofman
FOLLOW OUR SOCIAL MEDIA:
➜Twitter: @AppSecPodcast
➜LinkedIn: The Application Security Podcast
➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast
Thanks for Listening!
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

376 Listeners

649 Listeners

1,026 Listeners

43 Listeners

8,051 Listeners

13 Listeners

4 Listeners

179 Listeners

192 Listeners

8,044 Listeners

73 Listeners

136 Listeners

45 Listeners

411 Listeners

2 Listeners