The Application Security Podcast

Hendrik Ewerlin -- Threat Modeling of Threat Modeling

Mar 5, 2024
Hendrik Ewerlin, a threat modeling advocate, discusses the importance of threat modeling in software development. He explores the role of threat modeling, emphasizing the dire consequences of overlooking this crucial process. Hendrik stresses the importance of adopting an effective, efficient, and satisfying process for successful security.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
INSIGHT

Threat Modeling Is Core To Security

  • Threat modeling is essential because security means being protected from danger and that requires identifying threats.
  • Treat threat modeling as the systematic way to answer "what can go wrong" and "what will we do about it."
ADVICE

Optimize For Usability

  • Design threat modeling processes around effectiveness, efficiency, and satisfaction to increase adoption.
  • Make the process usable so people can complete models with good quality, low cost, and some enjoyment.
ADVICE

Start With Phase Zero

  • Create a Phase Zero: a clear, actionable 'how do we threat model' path so teams can start immediately.
  • Provide paved-road guidance and version-one experiments instead of waiting for a perfect process.
Get the Snipd Podcast app to discover more snips from this episode
Get the app