
Mark Loveless -- Threat modeling in a DevSecOps environment.
Om avsnittet
Threat modeling needs to fit the way developers work if it is going to survive a fast delivery cycle. Mark Loveless, also known as Simple Nomad, explains how GitLab adapted its approach for an asynchronous DevSecOps environment. He describes moving ownership toward the people building a project, introducing lightweight checkpoints, and making the process useful beyond engineering. The discussion explores a simplified version of PASTA, ordinary language instead of security jargon, and documentation that lives in familiar tools. Mark shares adoption tactics and examples of teams identifying risks for themselves. Throughout, he argues that security specialists should provide a usable framework and practical support while helping everyone develop the habit of asking what could go wrong.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Mark Loveless:
→ Mark Loveless’s website
Mentioned in this episode:
→ Mark’s GitLab threat modeling article
→ PASTA threat modeling
→ Mermaid diagrams
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 Threat modeling at GitLab with Mark Loveless
01:44 Mark’s security origin story
05:04 The GitLab threat modeling article series
06:11 Adapting threat modeling to DevSecOps
08:58 Starting threat modeling without disrupting flow
10:33 Where modeling fits in developer workflows
13:09 Extending threat modeling beyond engineering
14:56 Encouraging teams to participate
19:03 Choosing and simplifying PASTA
23:19 Using plain language instead of jargon
25:12 Writing models with familiar tools
26:55 Adoption stories and signs of success
33:18 Key takeaways and getting started
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.