Continuous Threat Modeling: Let Developers Figure It Out

Izar Tarandach
Izar Tarandach
Sr. Principal Security Architect,
Abstract

Threat Modeling has customarily been seen as a black art,a bit of an arcane discipline that not many are privy to. And that is, basically, wrong. Everyone threat models, all the time. And they very well should!\n\nIn this talk we will look at a couple of traditional Threat Modeling methodologies, what they're good for, what they miss, and offer a new one that your developers can run with - agile and principle-based. \nAfter that we will look at a threat-modeling-with-code tool, OWASP pytm, that can be used to support continuous threat modeling by your teams, see how it helps and what it doesn't do.