• DocumentCode
    1500576
  • Title

    Threat Modeling - Perhaps It´s Time

  • Author

    Steven, John

  • Author_Institution
    Cigital
  • Volume
    8
  • Issue
    3
  • fYear
    2010
  • Firstpage
    83
  • Lastpage
    86
  • Abstract
    Practitioners and researchers have been thinking about, making presentations on, and publishing material related to threat modeling for longer than many security practitioners performing assessments have been alive. Yet, many security managers avoid even discussing threat modeling because they perceive it as expensive and difficult. A noisy IT security space makes discerning real threat-modeling progress from bluster tricky. Accordingly, security managers resist revisiting previously considered techniques, until the community creates a demonstrably simpler, cheaper, or more scalable solution-often in product form. In the absence of such a threat modeling tool, at least commercially, you might be tempted to carry on deferring.
  • Keywords
    security of data; publishing material; security managers; security practitioners; threat modeling tool; Publishing; Resists; Security; Elevation of Privilege; OWASP; security and privacy; software engineering; threat modeling; top-N lists;
  • fLanguage
    English
  • Journal_Title
    Security & Privacy, IEEE
  • Publisher
    ieee
  • ISSN
    1540-7993
  • Type

    jour

  • DOI
    10.1109/MSP.2010.110
  • Filename
    5470962