Главная
Study mode:
on
1
Intro
2
Threat Modeling - what & why
3
A Threat Modeling (ongoing) personal journey
4
Did those methods reach the goals?
5
The Case For Continuous TM
6
Threat Model Every Story
7
Handbook and Subject areas
8
Principles Checklist
9
Threat Modeling Timeline
10
Reactions from product teams
11
Three current practical approaches
12
PyTM - Elements and Attributes
13
PyTM - Report template
Description:
Explore a team-based collaborative and continuous threat modeling methodology in this 49-minute conference talk from AppSecCali 2019. Discover how Autodesk is adapting to the challenges of agile development by moving away from traditional waterfall approaches and integrating threat modeling into the ongoing design process. Learn about the shift in dependency from security SMEs to development teams and gain insights into PyTM, an open-source threat-modeling-as-code support system. Delve into practical approaches for implementing continuous threat modeling, including principles checklists, threat modeling timelines, and reactions from product teams. Gain valuable knowledge on how to effectively integrate security considerations throughout the development lifecycle in fast-paced, agile environments.

Threat Model Every Story - Practical Continuous Threat Modeling Work for Your Team

OWASP Foundation
Add to list
0:00 / 0:00