Artwork

Content provided by Chris Romeo and Robert Hurlbut, Chris Romeo, and Robert Hurlbut. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Chris Romeo and Robert Hurlbut, Chris Romeo, and Robert Hurlbut or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.
Player FM - Podcast App
Go offline with the Player FM app!

Brett Crawley -- Threat Modeling Gameplay with EoP

45:28
 
Share
 

Manage episode 454790308 series 2540720
Content provided by Chris Romeo and Robert Hurlbut, Chris Romeo, and Robert Hurlbut. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Chris Romeo and Robert Hurlbut, Chris Romeo, and Robert Hurlbut or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.

Brett Crawley discusses the Elevation of Privilege (EoP) card game, a powerful tool for threat modeling in software development. The discussion explores recent extensions to the game including privacy-focused suits and TRIM (Transfer, Retention/Removal, Inference, Minimization) categories. Crawley emphasizes that threat modeling shouldn't end with the game but should be an ongoing process throughout an application's lifecycle, ideally starting before implementation. He also shares insights from his book, which provides detailed examples and guidance for teams new to threat modeling using EoP.
You can find Brett on X @brettcrawley

Brett’s book:
Threat Modeling Gameplay with EoP: A reference manual for spotting threats in software architecture
Book recommendation:
Conscious Business by Fred Kofman

FOLLOW OUR SOCIAL MEDIA:

➜Twitter: @AppSecPodcast
➜LinkedIn: The Application Security Podcast
➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast

Thanks for Listening!

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

  continue reading

285 episodes

Artwork
iconShare
 
Manage episode 454790308 series 2540720
Content provided by Chris Romeo and Robert Hurlbut, Chris Romeo, and Robert Hurlbut. All podcast content including episodes, graphics, and podcast descriptions are uploaded and provided directly by Chris Romeo and Robert Hurlbut, Chris Romeo, and Robert Hurlbut or their podcast platform partner. If you believe someone is using your copyrighted work without your permission, you can follow the process outlined here https://ppacc.player.fm/legal.

Brett Crawley discusses the Elevation of Privilege (EoP) card game, a powerful tool for threat modeling in software development. The discussion explores recent extensions to the game including privacy-focused suits and TRIM (Transfer, Retention/Removal, Inference, Minimization) categories. Crawley emphasizes that threat modeling shouldn't end with the game but should be an ongoing process throughout an application's lifecycle, ideally starting before implementation. He also shares insights from his book, which provides detailed examples and guidance for teams new to threat modeling using EoP.
You can find Brett on X @brettcrawley

Brett’s book:
Threat Modeling Gameplay with EoP: A reference manual for spotting threats in software architecture
Book recommendation:
Conscious Business by Fred Kofman

FOLLOW OUR SOCIAL MEDIA:

➜Twitter: @AppSecPodcast
➜LinkedIn: The Application Security Podcast
➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast

Thanks for Listening!

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

  continue reading

285 episodes

All episodes

×
 
Loading …

Welcome to Player FM!

Player FM is scanning the web for high-quality podcasts for you to enjoy right now. It's the best podcast app and works on Android, iPhone, and the web. Signup to sync subscriptions across devices.

 

Quick Reference Guide

Listen to this show while you explore
Play