DocumentCode :
1500576
Title :
Threat Modeling - Perhaps It´s Time
Author :
Steven, John
Author_Institution :
Cigital
Volume :
8
Issue :
3
fYear :
2010
Firstpage :
83
Lastpage :
86
Abstract :
Practitioners and researchers have been thinking about, making presentations on, and publishing material related to threat modeling for longer than many security practitioners performing assessments have been alive. Yet, many security managers avoid even discussing threat modeling because they perceive it as expensive and difficult. A noisy IT security space makes discerning real threat-modeling progress from bluster tricky. Accordingly, security managers resist revisiting previously considered techniques, until the community creates a demonstrably simpler, cheaper, or more scalable solution-often in product form. In the absence of such a threat modeling tool, at least commercially, you might be tempted to carry on deferring.
Keywords :
security of data; publishing material; security managers; security practitioners; threat modeling tool; Publishing; Resists; Security; Elevation of Privilege; OWASP; security and privacy; software engineering; threat modeling; top-N lists;
fLanguage :
English
Journal_Title :
Security & Privacy, IEEE
Publisher :
ieee
ISSN :
1540-7993
Type :
jour
DOI :
10.1109/MSP.2010.110
Filename :
5470962
Link To Document :
بازگشت