YoVDO

Automating Architectural Risk Analysis with Open Threat Model Format

Offered By: OWASP Foundation via YouTube

Tags

Threat Modeling Courses DevSecOps Courses Software Architecture Courses Software Security Courses Continuous Integration Courses Infrastructure as Code Courses

Course Description

Overview

Save Big on Coursera Plus. 7,000+ courses at $160 off. Limited Time Only!
Explore the automation of architectural risk analysis using the Open Threat Model format in this 47-minute OWASP Foundation conference talk by Fraser Scott, VP of Product at IriusRisk. Delve into the challenges of manual security workshops and discover how Infrastructure as Code can streamline the process. Learn about the Open Threat Model (OTM) format and its implementation in DevSecOps workflows. Gain insights into architectural risk analysis, threat modeling, and shifting security left in software development. Examine the differences between software development and manufacturing, and understand the continuous iterative revisionist design approach. Discover practical applications of the OTM format, its key features, and potential use cases through a comprehensive demonstration.

Syllabus

Introduction
What is architecture
What is architectural risk analysis
Insecure design
Threat modelling
Shifting security left
Architecture challenges
Software development vs manufacturing
Software development is art
Continuous iterative revisionist design
Canvas framework
Warding map
Continuous iterative revisionist
Infrastructure as code
Open threat model format
Potential use cases
Open specification
Object attributes
Key differences
Unique Identifiers
Representations
Application Code
Trust Zones
Components
Data Flow
Threats
Mitigations
Component
Demo


Taught by

OWASP Foundation

Related Courses

Pattern-Oriented Software Architectures: Programming Mobile Services for Android Handheld Systems
Vanderbilt University via Coursera
Engineering Maintainable Android Apps
Vanderbilt University via Coursera
Software Design as an Element of the Software Development Lifecycle
University of Colorado System via Coursera
Secure Software Development
Pluralsight
Secure Software Concepts for CSSLPĀ®
Pluralsight