<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>High-Level Threat Modelling Process</title><link>http://blogs.msdn.com/b/ptorr/archive/2005/02/08/368881.aspx</link><description>The following is a (slightly modified) version of a document I wrote for the VSTO team way back in the day. You might find it useful as you plan threat modelling for your product(s). You should of course read the Threat Modelling book from Microsoft Press</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>High Level Network Threat Modeling</title><link>http://blogs.msdn.com/b/ptorr/archive/2005/02/08/368881.aspx#459353</link><pubDate>Fri, 02 Sep 2005 00:05:04 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:459353</guid><dc:creator>Peter Torr - MSFT</dc:creator><description>Dana Epp has a great article at &lt;a rel="nofollow" target="_new" href="http://silverstr.ufies.org/blog/archives/000851.html"&gt;http://silverstr.ufies.org/blog/archives/000851.html&lt;/a&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=459353" width="1" height="1"&gt;</description></item><item><title>What is Microsoft doing for security?</title><link>http://blogs.msdn.com/b/ptorr/archive/2005/02/08/368881.aspx#452455</link><pubDate>Wed, 17 Aug 2005 05:32:47 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:452455</guid><dc:creator>Office Development, Security, Randomness...</dc:creator><description>&lt;br&gt;    &lt;br&gt;      &lt;br&gt;        A recent comment on the IE Blog made it pretty apparent that not everybody is aware...&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=452455" width="1" height="1"&gt;</description></item><item><title>Guerrilla Threat Modelling (or 'Threat Modeling' if you're American)</title><link>http://blogs.msdn.com/b/ptorr/archive/2005/02/08/368881.aspx#381138</link><pubDate>Sun, 27 Feb 2005 09:49:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:381138</guid><dc:creator>Office Development, Security, Randomness...</dc:creator><description>A crash-course in developing Data Flow Diagrams in support of software threat models&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=381138" width="1" height="1"&gt;</description></item><item><title>re: High-Level Threat Modelling Process</title><link>http://blogs.msdn.com/b/ptorr/archive/2005/02/08/368881.aspx#378515</link><pubDate>Wed, 23 Feb 2005 01:54:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:378515</guid><dc:creator>Peter Torr</dc:creator><description>More info on building DFDs is now available at:&lt;br&gt;&lt;br&gt;&lt;a target="_new" href="http://weblogs.asp.net/ptorr/archive/2005/02/22/378510.aspx"&gt;http://weblogs.asp.net/ptorr/archive/2005/02/22/378510.aspx&lt;/a&gt;&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=378515" width="1" height="1"&gt;</description></item><item><title>re: High-Level Threat Modelling Process</title><link>http://blogs.msdn.com/b/ptorr/archive/2005/02/08/368881.aspx#369688</link><pubDate>Wed, 09 Feb 2005 09:20:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:369688</guid><dc:creator>Stefan Keller</dc:creator><description>Not bad, but you end early. &lt;br&gt;- I always thought that other key benefits to do threat modelling are, that you could &lt;br&gt;a) show the morons that want to introduce insecurity later on in the project, what that will do to them easily and illustratively&lt;br&gt;b) have a readily available, nice residual risk piece for final sign-off&lt;br&gt;&lt;br&gt;Regards&lt;br&gt;&lt;br&gt;Stefan &lt;br&gt;&lt;br&gt; &lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=369688" width="1" height="1"&gt;</description></item><item><title>re: High-Level Threat Modelling Process</title><link>http://blogs.msdn.com/b/ptorr/archive/2005/02/08/368881.aspx#369557</link><pubDate>Wed, 09 Feb 2005 01:57:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:369557</guid><dc:creator>Peter Torr</dc:creator><description>Some of us don't have certificates, you insensitive clod!&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=369557" width="1" height="1"&gt;</description></item><item><title>re: High-Level Threat Modelling Process</title><link>http://blogs.msdn.com/b/ptorr/archive/2005/02/08/368881.aspx#369447</link><pubDate>Tue, 08 Feb 2005 22:42:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:369447</guid><dc:creator>Insensitive Clod</dc:creator><description>But was your threat model DIGITALLY SIGNED?&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=369447" width="1" height="1"&gt;</description></item><item><title>High level Threat Modelling</title><link>http://blogs.msdn.com/b/ptorr/archive/2005/02/08/368881.aspx#369146</link><pubDate>Tue, 08 Feb 2005 19:45:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:369146</guid><dc:creator>Dana Epp's ramblings at the Sanctuary</dc:creator><description>Peter Torr has an interesting article/a&amp;gt; about high level threat modeling. The gist of his article is that the process consists of six (possibly repeated) steps, outlined below in more detail: Preparation Brainstorming Drafting Review Verification Closure I highly recommend you go read his article to dig into the depth of each step. Good job Peter....&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=369146" width="1" height="1"&gt;</description></item><item><title>Threat Modeling book review</title><link>http://blogs.msdn.com/b/ptorr/archive/2005/02/08/368881.aspx#368960</link><pubDate>Tue, 08 Feb 2005 13:14:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:368960</guid><dc:creator>Sergey Simakov blog</dc:creator><description>&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.msdn.com/aggbug.aspx?PostID=368960" width="1" height="1"&gt;</description></item></channel></rss>