Discover the (ISC)² Community 

Join the ISC2 Community and share your cybersecurity knowledge and experience with other pros – (ISC)² members and non-members alike!

 

Threat Modeling Wins for Agile AppSec

“There are two ways of constructing a software design. One way is to make it so simple that there are obviously no deficiencies. And the other way is to make it so complicated that there are no obvious deficiencies” - CAR Hoare

Threat modeling for long has been a “design level” activity that fit in right at the beginning of a well defined application security strategy, and rightfully so. However, the current speed and scale of product and security engineering has forced software teams to overlook this very critical element of software security...and rightfully so!

What the audience would take away from the talk

  • The context of Threat Modeling in the current state of Product Engineering

  • The problem with Threat Modeling today

  • A compare and contrast of Component Driven and Offense Driven Threat Modeling

  • Threat Modeling as a route to better test case design and automation

  • Threat Modeling as Code using ThreatPlayBook

Rahul Raghavan

  Rahul Raghavan Speaker we45

The sheer pervasiveness of applications, their associated software engineering process and therefore the variance of application security quotient across software teams is what drives Rahul’s primary role as an AppSec Advocate at we45. Having worked on both the building and breaking sides of product engineering, Rahul appreciates both the constraints and the opportunities of imbibing security within the software lifecycle. This understanding created a natural segue for we45’s custom security solution engineering and enhanced AppSec service delivery models for its global customers. As an active DevSecOps Marketer, Rahul works closely with the offices of CTOs and CIOs in the setting up of cross functional skill building and collaboration models between engineering, QA and security teams to build and manage software security maturity frameworks.

Rahul is Certified Information Systems Auditor (CISA) and is a regular speaker at global conferences, seminars and meetup groups on the following topic areas

1. Application Security Automation and DevSecOps
2. AppSec Tooling
3. Threat Modeling in Agile Engineering
4. QA: Security Mapping
5. Automation ROI Modelling
6. AWS Security
7. Secure Software Maturity Models

Event Date: Tuesday June 16, 2020 at 7:00 PM

This event will be a Virtual Workshop. Please RSVP at the link below to register in advance 

https://us02web.zoom.us/webinar/register/WN_UOmCVhnbQqqmzM1H6SdAEA 

2 CPEs per event (to be tracked by the ISC² Ottawa chapter).