Skip to main content
  • 378 Topics
  • 434 RepliesReplies
  • 123 Members

    44 Ideas

    Create Your First Threat Model Using a Spreadsheet (Template, Recording, Deck Included)Im Voting 123

    About this workshopIn this workshop, you’ll learn the basics of threat modeling and apply the knowledge to create a threat model following six steps right in a spreadsheet. The six-step spreadsheet template is based on the STRIDE framework, one of the most popular security threat modeling methodologies.Agenda Recording Template, Written Guide, Slide Deck About the workshop leaderAgenda Introduction to Threat Modeling What’s threat modeling Threat Modeling classification: STRIDE Threat Modeling elements Threat Modeling process: the four-question framework Applying STIDE to Threat Modeling elements Cloud Threat Modeling Demo: using the six-step spreadsheet template to create a threat model for a two-tier web application Recording  Template, Written Guide, Slide DeckTemplate: https://docs.google.com/spreadsheets/d/1AbouySzNorXs7sXwnMkZYkGdWeKESnJtKK_JfiTXBIE/edit?usp=sharing Written guide for how to use this template A Step-by-step Guide to Create Your First Threat Model (Template Included)GUIDE Slide deck in the attachment About the workshop leaderShankar Chebrolu (@shankarbabu) is a Director at Red Hat, Inc., leading the efforts of information risk assessments to identify and manage risks within various business & IT services hosting personal and other sensitive data. Shankar curated and maintained Red Hat’s enterprise security standards and collaborated with various internal teams and vendors to help Red Hat maintain compliance against various industry standard security frameworks and global privacy laws. Shankar coordinated and delivered over 100+ security education sessions in Red Hat to enhance the overall security awareness at the enterprise level. Shankar initiated and has been working to mature the Threat Modeling practice at Red Hat. Shankar is also working on establishing enterprise risk quantification program which helps to effectively communicate information risk in financial terms. Shankar is also a founding member of Threat Modeling Connect.

    //Terms and Conditions