OWASP SAMM User Day Lisbon 2024
Hosted by Jonathan Marcil
Wednesday, June 26th
THREAT MODELING DISCUSSION
What is Threat Modeling?
Threat modeling is a structured activity for identifying, evaluating, and managing system threats, architectural design flaws, and recommended security mitigations
Threat Modeling Philosophical Supplement
Have you ever asked yourself if the core values and principles reflected in your activities are aligned with that has been observed elsewhere to get good results?
https://www.threatmodelingmanifesto.org/
Objectives of this session
Threat Modeling relationship
to the rest of OWASP SAMM
quick overview
Threat Modeling outputs
Threat Modeling adjacent dynamics
Threat Modeling ingest / leverage
What are your examples of relationships between security practices?
What approach clearly provided value and success for your security posture?
Next:
Jonathan’s examples bank
Threat Modeling Informs Risk Profile
Threat Modeling <> Security Requirements
Threat Modeling <> Verification
Threat Modeling Dataflows == Data Elements
Threat Modeling <> Architecture Assessment
Thanks!
Slides and links on:
https://about.jonathanmarcil.ca →
Special thanks to:
Seba
Threat Modeling Manifesto Group