YoVDO

Learning Threat Modeling for Security Professionals

Offered By: LinkedIn Learning

Tags

Threat Intelligence Courses Risk Assessment Courses Threat Modeling Courses

Course Description

Overview

Threat modeling helps security professionals understand what can go wrong—and what to do about it. Learn to use the four-question and STRIDE frameworks for threat modeling.

Syllabus

Introduction
  • Develop secure products
  • Why would you threat model?
  • A simple approach to threat modeling
1. The Four Question Framework
  • What are we working on?
  • What can go wrong?
  • What are we going to do about it?
  • Did we do a good job?
2. STRIDE
  • Spoofing a specific server
  • Tampering with a file
  • Interlude: Scope and timing
  • Repudiating an order
  • Information disclosure
  • Denial of service
  • Elevation of privilege
  • Expansion of authority
Conclusion
  • Next steps

Taught by

Adam Shostack

Related Courses

Менеджмент информационной безопасности
Higher School of Economics via Coursera
Planning a Security Incident Response
Microsoft via edX
Identifying Security Vulnerabilities
University of California, Davis via Coursera
Secure Coding Practices
University of California, Davis via Coursera
Atlas Security
MongoDB University