Explore the automation of architectural risk analysis using the Open Threat Model format in this 47-minute OWASP Foundation conference talk by Fraser Scott, VP of Product at IriusRisk. Delve into the challenges of manual security workshops and discover how Infrastructure as Code can streamline the process. Learn about the Open Threat Model (OTM) format and its implementation in DevSecOps workflows. Gain insights into architectural risk analysis, threat modeling, and shifting security left in software development. Examine the differences between software development and manufacturing, and understand the continuous iterative revisionist design approach. Discover practical applications of the OTM format, its key features, and potential use cases through a comprehensive demonstration.
Automating Architectural Risk Analysis with Open Threat Model Format