DiscoverThe Application Security PodcastBrett Crawley -- Threat Modeling Gameplay with EoP
Brett Crawley -- Threat Modeling Gameplay with EoP

Brett Crawley -- Threat Modeling Gameplay with EoP

Update: 2024-12-10
Share

Description

Brett Crawley discusses the Elevation of Privilege (EoP) card game, a powerful tool for threat modeling in software development. The discussion explores recent extensions to the game including privacy-focused suits and TRIM (Transfer, Retention/Removal, Inference, Minimization) categories. Crawley emphasizes that threat modeling shouldn't end with the game but should be an ongoing process throughout an application's lifecycle, ideally starting before implementation. He also shares insights from his book, which provides detailed examples and guidance for teams new to threat modeling using EoP.

You can find Brett on X @brettcrawley

Brett’s book:
Threat Modeling Gameplay with EoP: A reference manual for spotting threats in software architecture

Book recommendation:
Conscious Business by Fred Kofman





FOLLOW OUR SOCIAL MEDIA:

➜Twitter: @AppSecPodcast
➜LinkedIn: The Application Security Podcast
➜YouTube: https://www.youtube.com/@ApplicationSecurityPodcast

Thanks for Listening!

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Comments 
In Channel
loading
00:00
00:00
x

0.5x

0.8x

1.0x

1.25x

1.5x

2.0x

3.0x

Sleep Timer

Off

End of Episode

5 Minutes

10 Minutes

15 Minutes

30 Minutes

45 Minutes

60 Minutes

120 Minutes

Brett Crawley -- Threat Modeling Gameplay with EoP

Brett Crawley -- Threat Modeling Gameplay with EoP

Chris Romeo and Robert Hurlbut