
Steven Wierckx -- The #OWASP Threat Modeling Project
Om avsnittet
Can a threat modeling community bring different methods together without forcing everyone into the same process? Steven Wierckx explains the goals of the OWASP Threat Modeling Project and the work that grew out of the security summit. He describes a vendor-neutral, methodology-neutral collection of knowledge organized around four questions: what are we building, what can go wrong, what will we do about it, and did we do enough? Chris and Robert explore how examples, reference models, and open discussion could help practitioners compare approaches and adapt them to agile development. Steven also explains the relationship between documentation and tools such as Threat Dragon. The episode closes with how working sessions and community contributions can turn shared experience into practical resources.
The Application Security Podcast is brought to you by Security Journey.
About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
→ Learn more about Security Journey
Connect with Steven Wierckx:
→ Steven Wierckx on LinkedIn
Mentioned in this episode:
→ OWASP Threat Modeling Project
→ OWASP Threat Dragon
→ Open Security Summit 2018 archive
Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook
Chapters:
00:00 The OWASP Threat Modeling Project
01:11 Steven’s security origin story
04:04 How the summit shaped the project
07:42 What methodology-neutral threat modeling means
10:46 The four common threat modeling questions
12:30 Building a community of practitioners
15:34 Example models and the project roadmap
20:05 How documentation and Threat Dragon fit together
24:15 Planning the Open Security Summit
27:48 Turning working sessions into published resources
30:28 How to participate in threat modeling
The Application Security Podcast med Chris Romeo and Robert Hurlbut finns tillgänglig på flera plattformar. Informationen på denna sida kommer från offentliga podd-flöden.