Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Adam Shostack – Threat Modeling – 5 Minute AppSec

2 min9 juli 2019

Om avsnittet

Why threat model when AppSec teams already have scanners, checklists, and testing? Adam Shostack argues that threat modeling is what makes those activities structured, systematic, and comprehensive instead of a collection of guesses. In this rapid 5 Minute AppSec, he explains how asking what you are building and what can go wrong focuses attention on the right parts of a system. Approaches such as STRIDE, attack trees, and kill chains help teams examine each element methodically, then use the results to guide the rest of the security program. Skip that step, Adam warns, and you are shooting in the dark. Stay through the end for a candid recording outtake.

Connect with Adam Shostack:
Adam Shostack on LinkedIn
Shostack + Associates

Mentioned in this episode:
Adam Shostack
Attack Trees (Schneier)
Cyber Kill Chain (Lockheed Martin)

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Why threat model?
00:10 Structured, systematic, and comprehensive security
01:07 The promised full interview
01:33 A candid recording outtake

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.