YoVDO

Lessons From the Threat Modeling Trenches

Offered By: OWASP Foundation via YouTube

Tags

Conference Talks Courses Threat Modeling Courses

Course Description

Overview

Explore lessons learned from building threat modeling practices across multiple organizations in this 52-minute conference talk by Brook Schoenfield, Principal Architect Product Security at McAfee. Gain insights from hundreds of students, years of coaching, numerous formal trainings, and thousands of threat models. Discover how threat modeling can reduce design errors and challenge conventional wisdom in application security. Learn about the importance of inclusivity, team collaboration, and allowing threat modeling to evolve within organizations. Examine the progression of threat modeling through different stages and its impact on prioritization, trust, architecture, and governance. Acquire valuable takeaways for implementing effective threat modeling practices and access resources for further learning in this OWASP Foundation presentation.

Syllabus

Introduction
Threat Modeling
My Experience
I Built
Threat Modeling Definition
Why is Threat Modeling Important
Design Misses
The Old Guard
Security becomes synonymous with no
Can you be different
Threat modeling becomes part of the woodwork
Its a team sport
Make it inclusive
Let it breathe and grow
Meltdown
Bronze Age
Iron Age
Crystal Ball
Prioritize
Trust
Architecture
Governance
Decentralization
Design Problem
Takeaways
Selfpromotion
Threat Modeling Library
Resources
CBS
Impacts


Taught by

OWASP Foundation

Related Courses

Building Geospatial Apps on Postgres, PostGIS, & Citus at Large Scale
Microsoft via YouTube
Unlocking the Power of ML for Your JavaScript Applications with TensorFlow.js
TensorFlow via YouTube
Managing the Reactive World with RxJava - Jake Wharton
ChariotSolutions via YouTube
What's New in Grails 2.0
ChariotSolutions via YouTube
Performance Analysis of Apache Spark and Presto in Cloud Environments
Databricks via YouTube