DocumentCode
1500576
Title
Threat Modeling - Perhaps It´s Time
Author
Steven, John
Author_Institution
Cigital
Volume
8
Issue
3
fYear
2010
Firstpage
83
Lastpage
86
Abstract
Practitioners and researchers have been thinking about, making presentations on, and publishing material related to threat modeling for longer than many security practitioners performing assessments have been alive. Yet, many security managers avoid even discussing threat modeling because they perceive it as expensive and difficult. A noisy IT security space makes discerning real threat-modeling progress from bluster tricky. Accordingly, security managers resist revisiting previously considered techniques, until the community creates a demonstrably simpler, cheaper, or more scalable solution-often in product form. In the absence of such a threat modeling tool, at least commercially, you might be tempted to carry on deferring.
Keywords
security of data; publishing material; security managers; security practitioners; threat modeling tool; Publishing; Resists; Security; Elevation of Privilege; OWASP; security and privacy; software engineering; threat modeling; top-N lists;
fLanguage
English
Journal_Title
Security & Privacy, IEEE
Publisher
ieee
ISSN
1540-7993
Type
jour
DOI
10.1109/MSP.2010.110
Filename
5470962
Link To Document