
Adam Shostack -- Fast, cheap and good threat models
The Application Security Podcast
00:00
Are You Processing Personal Information?
When i've thought of questionaires in the past, i think of questionairs as being closer to a set of requirements. So for example, when we talk about, are you processing personal information? The reason we're talking about that question from security is because of the threat of disclosure or inappropriate use. And so we can frame it as, here's a requirement question. There's other things that will often go in, such as, are you using p hp? Are you using dynamic sequel? Which are more closely i co vulnerability structures a.
Transcript
Play full episode