<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>High-Level Threat Modelling Process</title><link>http://blogs.msdn.com/ptorr/archive/2005/02/08/368881.aspx</link><description>The following is a (slightly modified) version of a document I wrote for the VSTO team way back in the day. You might find it useful as you plan threat modelling for your product(s). You should of course read the Threat Modelling book from Microsoft Press</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Threat Modeling book review</title><link>http://blogs.msdn.com/ptorr/archive/2005/02/08/368881.aspx#368960</link><pubDate>Tue, 08 Feb 2005 13:14:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:368960</guid><dc:creator>Sergey Simakov blog</dc:creator><description /></item><item><title>High level Threat Modelling</title><link>http://blogs.msdn.com/ptorr/archive/2005/02/08/368881.aspx#369146</link><pubDate>Tue, 08 Feb 2005 19:45:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:369146</guid><dc:creator>Dana Epp's ramblings at the Sanctuary</dc:creator><description>Peter Torr has an interesting article/a&amp;gt; about high level threat modeling. The gist of his article is that the process consists of six (possibly repeated) steps, outlined below in more detail: Preparation Brainstorming Drafting Review Verification Closure I highly recommend you go read his article to dig into the depth of each step. Good job Peter....</description></item><item><title>re: High-Level Threat Modelling Process</title><link>http://blogs.msdn.com/ptorr/archive/2005/02/08/368881.aspx#369447</link><pubDate>Tue, 08 Feb 2005 22:42:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:369447</guid><dc:creator>Insensitive Clod</dc:creator><description>But was your threat model DIGITALLY SIGNED?</description></item><item><title>re: High-Level Threat Modelling Process</title><link>http://blogs.msdn.com/ptorr/archive/2005/02/08/368881.aspx#369557</link><pubDate>Wed, 09 Feb 2005 01:57:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:369557</guid><dc:creator>Peter Torr</dc:creator><description>Some of us don't have certificates, you insensitive clod!</description></item><item><title>re: High-Level Threat Modelling Process</title><link>http://blogs.msdn.com/ptorr/archive/2005/02/08/368881.aspx#369688</link><pubDate>Wed, 09 Feb 2005 09:20:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:369688</guid><dc:creator>Stefan Keller</dc:creator><description>Not bad, but you end early. &lt;br&gt;- I always thought that other key benefits to do threat modelling are, that you could &lt;br&gt;a) show the morons that want to introduce insecurity later on in the project, what that will do to them easily and illustratively&lt;br&gt;b) have a readily available, nice residual risk piece for final sign-off&lt;br&gt;&lt;br&gt;Regards&lt;br&gt;&lt;br&gt;Stefan &lt;br&gt;&lt;br&gt; </description></item><item><title>re: High-Level Threat Modelling Process</title><link>http://blogs.msdn.com/ptorr/archive/2005/02/08/368881.aspx#378515</link><pubDate>Wed, 23 Feb 2005 01:54:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:378515</guid><dc:creator>Peter Torr</dc:creator><description>More info on building DFDs is now available at:&lt;br&gt;&lt;br&gt;&lt;a target="_new" href="http://weblogs.asp.net/ptorr/archive/2005/02/22/378510.aspx"&gt;http://weblogs.asp.net/ptorr/archive/2005/02/22/378510.aspx&lt;/a&gt;</description></item><item><title>Guerrilla Threat Modelling (or 'Threat Modeling' if you're American)</title><link>http://blogs.msdn.com/ptorr/archive/2005/02/08/368881.aspx#381138</link><pubDate>Sun, 27 Feb 2005 09:49:00 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:381138</guid><dc:creator>Office Development, Security, Randomness...</dc:creator><description>A crash-course in developing Data Flow Diagrams in support of software threat models</description></item><item><title>What is Microsoft doing for security?</title><link>http://blogs.msdn.com/ptorr/archive/2005/02/08/368881.aspx#452455</link><pubDate>Wed, 17 Aug 2005 05:32:47 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:452455</guid><dc:creator>Office Development, Security, Randomness...</dc:creator><description>&lt;br&gt;    &lt;br&gt;      &lt;br&gt;        A recent comment on the IE Blog made it pretty apparent that not everybody is aware...</description></item><item><title>High Level Network Threat Modeling</title><link>http://blogs.msdn.com/ptorr/archive/2005/02/08/368881.aspx#459353</link><pubDate>Fri, 02 Sep 2005 00:05:04 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:459353</guid><dc:creator>ptorr</dc:creator><description>Dana Epp has a great article at &lt;a rel="nofollow" target="_new" href="http://silverstr.ufies.org/blog/archives/000851.html"&gt;http://silverstr.ufies.org/blog/archives/000851.html&lt;/a&gt;</description></item></channel></rss>