This post originated from an RSS feed registered with .NET Buzz
by Robert Hurlbut.
Original Post: Guerrilla Threat Modelling
Feed Title: Robert Hurlbut's .Net Blog
Feed URL: http://www.asp.net/err404.htm?aspxerrorpath=/rhurlbut/Rss.aspx
Feed Description: Development with .Net, Rotor, Distributed Architectures, Security, Extreme Programming, and Databases
I saw this last night, and Dana Epp has posted a pointer:
Peter Torr has done it again. He has written an EXCELLENTarticle on writing a practical threat model... getting rid of the cruft of useless theory and applying real-world experience to how to get it done. If you are part of a team that needs a no nonsense approach to threat modeling, you should read his article on "Guerrilla Threat Modelling". Well worth the investment in time.
I agree -- this is excellent! Read it, learn it, and think about how to apply it to your own projects.