Threat Modeling Essentials (201)
from Shostack + Associates
The Threat Modeling Essentials course is designed to provide attendees the ability to more consistently and efficiently apply threat modeling using the Four Question Framework:
After taking Threat Modeling Essentials, participants will have the knowledge and skills to consistently and efficiently use the Four Question Framework, data flow diagrams, STRIDE to identify threats, mitigation techniques, document results, and advance threat modeling results for action.
The Threat Modeling Essentials course focuses on teaching a single method to address Four Questions. In intensive, we add more methods to address each, and learn to assess which to apply. That includes state machines and message diagrams to express what we're working on, kill chains and attack trees to address what can go wrong, and risk management approaches to bring more nuance to what we're going to do about each.
Formerly called "engineers," we've renamed this course to better reflect that it's great for anyone building products — software engineers, program managers, product managers, scrum masters, SOC engineers and others have enjoyed the course.