
Threat Modeling With Good Questions and Without Checklists - Farshad Abasi - ASW #335
Security Weekly Podcast Network (Audio)
00:00
Navigating Threat Modeling in Application Security
This chapter outlines the speaker's 17-year journey into application security, emphasizing the significance of threat modeling projects. It critiques the STRIDE framework, exploring its practical applicability while advocating for engaging developers in the process. The discussion also highlights the importance of documentation, user stories, and an iterative approach to effectively identify vulnerabilities in software applications.
Transcript
Play full episode