A Surprising Capability of Threat Modeling in Software Development

A Surprising Capability of Threat Modeling in Software Development

When developing software, whether employing the older waterfall methodology or one of the new agile methodologies, everything starts with requirements. No requirements, no software. When developers think about turning requirements into software, what they primarily...
The High Cost of Using Free Threat Modeling Tools – Part 3

The High Cost of Using Free Threat Modeling Tools – Part 3

NOTE: This is part three of a three-part series on making the business case for using commercial threat modeling tools. In part one, we put a dollar figure on the cost of a missed threat. In part two, we put a dollar figure on the extra hours required to produce a...
The High Cost of Using Free Threat Modeling Tools – Part 2

The High Cost of Using Free Threat Modeling Tools – Part 2

NOTE: This is part two of a three-part series on making the business case for using commercial threat modeling tools. In part one, we put a dollar figure on the cost of a missed threat. In part two, we’ll put a dollar figure on the extra hours required to produce a...
The High Cost of Using Free Threat Modeling Tools – Part 1

The High Cost of Using Free Threat Modeling Tools – Part 1

NOTE: This is part one of a three part series on making the business case for using commercial threat modeling tools. Anyone that’s been around the block software wise can tell you that as things start to really scale up, using free, open source software quickly...
Threat Modeling is a Process not a Project

Threat Modeling is a Process not a Project

Developers are starting to embrace the idea that threat modeling is a best practice as part of the secure development lifecycle (SDLC). And if it is, it can no longer be seen as a project. It must evolve into a process. A Project vs a Process Projects and processes...