Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Irene Michlin -- We Are Not Making It Worse

33 min9 februari 2018

Om avsnittet

When a team is already ten sprints into a product, stopping to threat model everything can sound impossible. Irene Michlin explains an incremental approach: examine the next change, keep the discussion bounded, and make sure new work does not make the system worse. Drawing on her experience as a developer and security practitioner, she describes how short exercises build confidence and how threat modeling improves testing and shared architectural understanding. Chris and Robert explore what to do about existing security debt, how to record threats in the team’s normal work tracker, and where security stories and acceptance criteria fit. Irene also discusses whiteboards, the Microsoft Threat Modeling Tool, and STRIDE, emphasizing a repeatable thinking habit that can keep pace with agile development.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Irene Michlin:
Irene Michlin on LinkedIn

Mentioned in this episode:
Microsoft Threat Modeling Tool

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Incremental threat modeling with Irene Michlin
01:21 Irene’s path from development into AppSec
05:05 Security products still need product security
06:41 The wider benefits of threat modeling
09:04 Starting with the next sprint’s changes
11:24 Handling existing security debt
13:46 Teaching a lightweight modeling process
17:21 Using a timer to build confidence
18:28 Keeping threats in the team’s work tracker
20:19 Security stories and acceptance criteria
23:16 Defining done for security work
24:24 Choosing tools for fast threat modeling
27:06 Using STRIDE as a foundation
29:07 Adding context-specific threats

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.