Threat Modeling Gameplay with EoP: A reference manual for spotting threats in software architecture
Author: Brett Crawley (Author)
Publisher finelybook 出版社:Packt Publishing
Edition 版本: N/A
Publication Date 出版日期: 2024-08-9
Language 语言: English
Print Length 页数: 256 pages
ISBN-10: 1804618977
ISBN-13: 9781804618974
Book Description
Book Description
Review
“I created the game, and hundreds of thousands of copies have been produced and used by people all around the world to learn and encourage threat modeling. Play-testing showed how powerful it could be. And there’s just something cool about going into a business meeting with a game. It’s going to be different, and if you suspend your skepticism, what happens can be magical…. And that’s why I’m so excited about the book you’re holding. Brett has stepped up to create a manual and open the world of security to a whole new audience.
Elevation of Privilege helped show that games can help us learn about or even deliver security. I encourage you to use the game, and this book, to empower those around you to deliver more secure systems.”
Adam Shostack, Creator of EoP
About the Author
Brett Crawley is a principal application security engineer, (ISC2) CISSP, CSSLP, and CCSP certified, the project lead on the OWASP Application Security Awareness Campaigns project, and the author of the OSTERING blog on security. He has published a Miro template for threat modeling with the Elevation of Privilege card game and also published the CAPEC S.T.R.I.D.E. mapping mind maps and other resources. With over 10 years of application security experience and over 25 years of software engineering experience, he works with teams to define their security best practices and introduce security by design into their existing SDLC, and as part of this initiative, he trains teams in threat modeling because good design is of key importance. He is also an advocate for using a data-driven approach to AppSec, to help identify the business-critical components, thereby optimizing the reduction of risk to the organization.
下载地址
相关推荐
- Dragnet Nation: A Quest for Privacy, Security, and Freedom in a World of Relentless Surveillance
- Bash Shell Scripting for Pentesters: Master the art of command-line exploitation and enhance your penetration testing workflows
- Practical HTML and CSS: Elevate your internet presence by creating modern and high-performance websites for the web
- Essential PostgreSQL: Your guide to database design, query optimization, and administration
- Mastering AWS Elastic Kubernetes Services: Building and deploying scalable containerized applications with Kubernetes and EKS
- Getting Started with JavaScript: A JavaScript Beginner's Guide to Building Dynamic Web and Mobile Apps with Hands-On Examples and 200+ Sample Projects