Sveriges mest populära poddar
The Application Security Podcast
The Application Security Podcast

Stephen de Vries -- Threat Modeling with a bit of #Startup

22 min20 augusti 2018

Om avsnittet

What developers need from a threat model is often a clear set of requirements they can implement. Stephen de Vries explains how that perspective shaped IriusRisk and his move from security consulting into building a product company. He and Chris discuss reusable threats and countermeasures, the role of OWASP ASVS, and the need to translate guidance into instructions that make sense in an issue tracker. They also examine why spreadsheets and separate security systems create friction, and how existing testing and design habits can provide a bridge into security. Stephen’s startup experience frames a broader conversation about making threat modeling repeatable: reuse what is known, focus human attention on the difficult parts, and meet developers inside their normal workflow.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Stephen de Vries:
Stephen de Vries on LinkedIn
IriusRisk

Mentioned in this episode:
OWASP Application Security Verification Standard
OWASP Proactive Controls
OWASP Web Security Testing Guide

Follow the Application Security Podcast:
Home
X
LinkedIn
YouTube
Instagram
➜ Facebook

Chapters:
00:00 Threat modeling and startup lessons with Stephen de Vries
00:34 Stephen’s development and security background
05:01 Starting a security product company
06:35 From building a product to building a company
07:48 Threat modeling as a route to security requirements
10:41 Reusing common threats and countermeasures
12:00 Connecting requirements management and threat modeling
13:43 Turning ASVS into actionable developer guidance
14:16 Meeting developers in their existing tools
15:33 Removing spreadsheet and email friction
17:00 Building on testing and design habits
18:41 Connecting everyday risk thinking to security
20:06 Behavior-driven testing and useful OWASP resources

The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.