Главная
Study mode:
on
1
Introduction
2
Agenda
3
The Challenge
4
The Threat Modeling Manifesto
5
What is Threat Modeling
6
Threat Modeling for Everyone
7
Why Did We Put This Together
8
The Four Key Questions
9
Benefits of Threat Modeling
10
Using the Manifesto
11
People in Collaboration
12
Journey of Understanding
13
iterative approach
14
threat modeling
15
the 30 minute rule
16
the principles
17
outcomes are meaningful
18
antipatterns
19
positive patterns
20
useful toolkit
21
choosing a solid process
22
embed threat modeling
23
threat modeling champions
24
teaching threat modeling
25
embracing stride
26
adapt with ASVS methodology
27
focus on mitigations
28
adopt the right tool sets
29
threat model quality checks
30
summary
Description:
Explore the fundamentals of building an Enterprise-class threat modeling program using the Threat Modeling Manifesto in this 57-minute LASCON conference talk. Learn why threat modeling is crucial in today's security landscape, how to leverage the manifesto created by 15 security experts, and gain practical tips for implementation. Discover the four key questions, benefits, and principles of effective threat modeling. Understand the importance of collaboration, iterative approaches, and the 30-minute rule. Delve into positive patterns, antipatterns, and useful toolkits for choosing a solid process. Learn strategies for embedding threat modeling in your organization, developing threat modeling champions, and teaching the practice. Explore how to adapt methodologies like STRIDE and ASVS, focus on mitigations, adopt the right tool sets, and perform quality checks on threat models.

Using the Threat Modeling Manifesto to Build an Enterprise Threat Modeling Program

LASCON
Add to list