What Could Possibly Go Wrong? Plain Language Threat Modeling in DevSecOps

No ratings

Presented at RSAC 2022 by

In this session, a co-author of the Threat Modeling Manifesto will show how capturing threat information in plain-language in the user-story breaks through roadblocks. A flow that removes security gates and integrates threat information in all phases of the lifecycle will be presented. Stop trying to predict attacker behaviors and instead focus on identifying critical assets and defenses.