31.08.2022 Views

Cyber Defense eMagazine September Edition for 2022 #CDM

#CYBERDEFENSEMAG @CyberDefenseMag by @Miliefsky a world-renowned cyber security expert and the Publisher of Cyber Defense Magazine as part of the Cyber Defense Media Group as well as Yan Ross, Editor-in-Chief and many more writers, partners and supporters who make this an awesome publication! Thank you all and to our readers! OSINT ROCKS! #CDM #CDMG #OSINT #CYBERSECURITY #INFOSEC #BEST #PRACTICES #TIPS #TECHNIQUES

#CYBERDEFENSEMAG @CyberDefenseMag by @Miliefsky a world-renowned cyber security expert and the Publisher of Cyber Defense Magazine as part of the Cyber Defense Media Group as well as Yan Ross, Editor-in-Chief and many more writers, partners and supporters who make this an awesome publication! Thank you all and to our readers! OSINT ROCKS! #CDM #CDMG #OSINT #CYBERSECURITY #INFOSEC #BEST #PRACTICES #TIPS #TECHNIQUES

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Threat Modeling: Bridging the Gap Between Developers<br />

and Security Architects<br />

By Stephen de Vries, Co-Founder and CEO of IriusRisk<br />

The application security world is known <strong>for</strong> friction between security and development teams. However,<br />

this tension can be eradicated through a development security strategy to bring developers and security<br />

architects together: threat modeling.<br />

Protection be<strong>for</strong>e it’s too late<br />

Threat modeling is the act of conducting security analysis be<strong>for</strong>e a system is finalised, or even built, to<br />

detect weaknesses and vulnerabilities in the design of the system and to plan <strong>for</strong> mitigating insecure<br />

design. It’s looking left and right on the street be<strong>for</strong>e crossing, rather than checking <strong>for</strong> cars when you’re<br />

in the middle of the road – looking <strong>for</strong> threats is better done sooner rather than later.<br />

Threat modeling can traditionally be done manually using a whiteboard, running as a workshop where<br />

security experts show the product team which practices to avoid or embrace to enhance security. It can<br />

<strong>Cyber</strong> <strong>Defense</strong> <strong>eMagazine</strong> – <strong>September</strong> <strong>2022</strong> <strong>Edition</strong> 117<br />

Copyright © <strong>2022</strong>, <strong>Cyber</strong> <strong>Defense</strong> Magazine. All rights reserved worldwide.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!