Making threat modelling easy and scalable using STRIDE

No ratings

Presented at KawaiiCon 2022 by

Do you think it sucks to do threat modelling and risk assessments every time you create an app or a feature? Isn’t this a function of the security team? Or do you work in security and don’t like developers or engineers treating this as a checkbox item? Why does that happen? Is it because of competing priorities, overwhelming processes, unclear requirements, non-technical people telling technical people how to do it, or something else? I decided to learn more about it - well basically speak to a lot of people about it and google the hell out of it. With some help and some trial and error, I came up with a way that strikes a balance between the effort on threat modelling vs the value + coverage it gives. Therefore something like 20% effort for 80% coverage. This short talk is about what I’ve learned and what worked for me. I am not claiming to be an expert in this domain and in fact this is my first big talk! But I’ll share a self-service* threat modelling template that I came up with, which can be used by teams in workshops for reviewing apps/services built on AWS. Hopefully you can use it too.