Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Adam Shostack -- Fast, cheap and good threat models

31 min15 december 2021

Om avsnittet

Adam is a leading expert on threat modeling, and a consultant, expert witness, author and game designer. He has decades of experience delivering security. His experience ranges across the business world from founding startups to nearly a decade at Microsoft. While not consulting or training, Shostack serves as an advisor to a variety of companies and academic institutions. Adam joins us to talk about fast, cheap, and good threat models. We discuss how Adam defines these categories, the weight of threat modeling, questionnaires/requirements, expertise, and how to make threat modeling conversational. We hope you enjoy this conversation with... Adam Shostack. You're about to listen to AppSec Podcast.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Adam Shostack is a leading expert on threat modeling and a consultant, expert witness, author, and game designer.
Learn more about Security Journey

Connect with Adam Shostack:
Shostack + Associates
Adam Shostack

Mentioned in this episode:
Shostack + Associates
Adam Shostack
Gary McGraw
OWASP Application Security Verification Standard (ASVS)
ATT&CK
MITRE ATT&CK Framework
Cyber Kill Chain (Lockheed Martin)

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Meet Adam Shostack: Fast, cheap and good threat models
03:15 Yeah, I want to unpack these 3 words a little bit
04:47 You're thinking cheap, are you thinking from a resources and time
07:38 We keep talking about and using that term heavyweight. Is threat
09:17 Yeah, one of the things that I've said since I first
12:24 Yeah, I'm tracking with you now as well about the fact
15:11 You mean the 3 questions that are being asked
20:48 Oh, and I was thinking similar. I always think about requirements
22:48 That— have you ever looked at like the ATT&CK methodology, for
24:21 That makes sense. But let's talk about what do you need
27:07 To kind of bring all these things together, Adam, we, all
29:34 What's the call to action then that you would offer to

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.