<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Application Security Development Lifecycle 5A: Is Threat Modeling Right For You?</title><link>http://blogs.msdn.com/akshay_aggarwal/archive/2008/06/11/application-security-development-lifecycle-5a-is-threat-modeling-right-for-you.aspx</link><description>Several enterprises are increasingly investing time and money in building application security tasks into their existing SDLCs. Some of them have also reached the conclusion that proactive approaches , like threat modeling, have more ROI than reactive</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: Application Security Development Lifecycle 5A: Is Threat Modeling Right For You?</title><link>http://blogs.msdn.com/akshay_aggarwal/archive/2008/06/11/application-security-development-lifecycle-5a-is-threat-modeling-right-for-you.aspx#8593443</link><pubDate>Thu, 12 Jun 2008 20:32:40 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8593443</guid><dc:creator>SME</dc:creator><description>&lt;p&gt;Excellent post once again. Webappsec programs are in different stages of maturity in different orgs. It's important to introduce the right thing (scanning, static code review,...) at the right time for best ROI. &amp;nbsp;This article makes a good case for when to introduce threat modeling.&lt;/p&gt;</description></item><item><title>Is Threat Modeling Right For You?</title><link>http://blogs.msdn.com/akshay_aggarwal/archive/2008/06/11/application-security-development-lifecycle-5a-is-threat-modeling-right-for-you.aspx#8619884</link><pubDate>Thu, 19 Jun 2008 05:37:25 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8619884</guid><dc:creator>Microsoft Application Threat Modeling Blog</dc:creator><description>&lt;p&gt;Great post by my friend and colleague around threat modeling in a series he's doing on application security&lt;/p&gt;
</description></item><item><title>http://entwickler.com/itr/news/psecom,id,42519,nodeid,82.html</title><link>http://blogs.msdn.com/akshay_aggarwal/archive/2008/06/11/application-security-development-lifecycle-5a-is-threat-modeling-right-for-you.aspx#8625084</link><pubDate>Fri, 20 Jun 2008 11:55:43 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8625084</guid><dc:creator>TrackBack</dc:creator><description /></item><item><title>MSDN FLASH IRELAND - INTERNATIONAL RESOURCES - 30 June 2008</title><link>http://blogs.msdn.com/akshay_aggarwal/archive/2008/06/11/application-security-development-lifecycle-5a-is-threat-modeling-right-for-you.aspx#8792841</link><pubDate>Thu, 31 Jul 2008 05:51:56 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8792841</guid><dc:creator>Microsoft Ireland Blog</dc:creator><description>&lt;p&gt;a {color : #0033CC;} a:link {color: #0033CC;} a:visited.local {color: #0033CC;} a:visited {color : #800080;}&lt;/p&gt;
</description></item><item><title>Is Threat Modeling Right For You?</title><link>http://blogs.msdn.com/akshay_aggarwal/archive/2008/06/11/application-security-development-lifecycle-5a-is-threat-modeling-right-for-you.aspx#8852537</link><pubDate>Tue, 12 Aug 2008 20:33:07 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:8852537</guid><dc:creator>Georgeo Pulikkathara's Microsoft Blog</dc:creator><description>&lt;p&gt;&amp;amp;#160; Be sure to check out Talhah Mir's blog on threat modeling. &lt;a rel="nofollow" target="_new" href="http://blogs.msdn.com/threatmodeling/"&gt;http://blogs.msdn.com/threatmodeling/&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>re: Application Security Development Lifecycle 5A: Is Threat Modeling Right For You?</title><link>http://blogs.msdn.com/akshay_aggarwal/archive/2008/06/11/application-security-development-lifecycle-5a-is-threat-modeling-right-for-you.aspx#9464764</link><pubDate>Sun, 08 Mar 2009 06:58:02 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:9464764</guid><dc:creator>Philip.Agcaoili</dc:creator><description>&lt;P&gt;Hey Akshay.&lt;/P&gt;
&lt;P&gt;What's interesting for us is where Threat Modeling worked and did not work. &amp;nbsp;&lt;/P&gt;
&lt;P&gt;We struggled to show success and ROSI for IT engagements, only obtaining 1-2 serious architectural and/or approach flaws using Threat Modeling. The environment is much more stable and there are more knowns, so TM seemed too trivial for some of our IT dev teams.&lt;/P&gt;
&lt;P&gt;For our Product development and Software as a Service offerings (SaaS or Cloud Computing), Threat Modeling is at the core of what we do to ensure sound architecture and fundamentals to each of these areas.&lt;/P&gt;
&lt;P&gt;Glad to see the tool is updated as well. We have been plodding along using Word/Visio templates for our Threat Models and hoping the tool works better for us this go around.&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Phil Agcaoili&lt;/P&gt;</description></item></channel></rss>