Other Diversions

security

politics

religion

technology

news

friends

Science / Skepticism


Powered by MT Blogroll

Latest Music

« ZDNet's "apology" to Google | Juxtaposition Home | Several stories that prove the world is going crazy »

Using threat modeling featured in new OWASP WAPT

This will be something to look forward to. I have not seen much of the theory of threat modeling end-to-end put into practice effectively or completely. And much of what I have seen of threat modeling really should be baked into the SDLC process and something that project teams do as part of normal development efforts (why are security people doing separate data flow diagrams, for example?).

From Threatsandcountermeasures:


The next release of the OWASP Web Application Penetration Test (WAPT) guide will include a section on using threat modelling effectively

Threat Modelling and security testing

TrackBack

TrackBack URL for this entry:
https://juxtaposition.axley.net/blog-bin/mt-tb.cgi/253

Post a comment

«« October 2007

Sun Mon Tue Wed Thu Fri Sat
  1 2 3 4 5 6
7 8 9 10 11 12 13
14 15 16 17 18 19 20
21 22 23 24 25 26 27
28 29 30 31      
Contact: Jason Axley

Search Amazon:

Amazon Logo