The objective of this course is to provide the delegates with a structured and streamlined threat modeling approach that aligns with any modern, quick-paced development environment. Delegates will achieve the following 3 training goals:
Goal 1: Clear understanding of where traditional threat modeling fails with modern software workflows
Goal 2: Using and linking publicly available security frameworks for threat and mitigation data (e.g. OWASP Top 10, Mitre CWE, AWS, Azure)
Goal 3: Introduction to Rapid Threat Model Prototyping, and Integrating into an Agile-based Environment
Training level: Basic; Intermediate
The following modules will be presented to the class:
Day 1
Day 2
Day 3
The lab is based on several scenarios which the students can pick, or they can choose their own scenarios from work.
There will be a number of smaller labs and presenter-led discussions per module. All labs are group-based, as opposed to individual activities. This model is what takes place in actual work environments.
Delegates should bring along laptops with access to a technical drawing tool (such as draw.io or Lucidcharts) and a spreadsheet app, for creating the links between the security frameworks.
The intended audience for this course is primarily system Developers, Designers, and Architects.
Anyone who understands the technical aspects of building and maintaining secure systems would also find this course very useful.
Geoff Hill worked for the past 5 years on Wall Street as a commodities trader. He created an options pricing program and sold the results daily on the NYC Commodities Exchange. He spent 8 years at Microsoft and created an Agile-focused SDL process for our customers.
Geoff has also developed threat model theories with Adam Shostack, the leading threat model specialist in the world. He worked for Cigital (a specialist security firm) for 2 years and then spent 4 years as a software security architect for Visa Europe. He has been a threat modeling and application security trainer for 10+ years.
Most importantly, he is a co-founder of an Agile-based threat model consultancy and the creator of the Tutamen automated threat modeling SaaS product (founder of Tutamantic_Sec).