Welcome to MSDN Blogs Sign in | Join | Help

News

SDL Threat Modeling: Past, Present and Future

Adam Shostack here.

I wanted to share my slides from the recent Layer One conference [link], where I talked about "SDL Threat Modeling: Past, Present and Future."

There are a few points that I wanted to emphasize. The first is that I'm talking about threat modeling from the perspective of the SDL. We have other threat modeling processes here at Microsoft, and we're working to bring you more clarity in how we speak about them. For my part, I'll try to clearly say "SDL threat modeling," or be explicit when I'm talking about threat modeling in broad terms.

Which brings me to my second point, and a slide I wanted to emphasize. (Shown here)

image001 

I no longer think of threat modeling as one thing. I see it as a label for a set of ways to address the question of "what could go wrong" with a design or set of requirements. The SDL has one process. The folks in ACE and Patterns and Practices each have another. All are customized to meet various needs. Much like we have lots of programming languages which address different problems, we're going to have lots of threat modeling processes.

Anyway, I hope you enjoy the slides.

Posted: Tuesday, June 17, 2008 2:59 PM by sdl
Filed under:

Comments

mortman said:

The link to the slides is broken...

# June 18, 2008 7:42 AM

Microsoft Ireland Blog said:

a {color : #0033CC;} a:link {color: #0033CC;} a:visited.local {color: #0033CC;} a:visited {color : #800080;}

# July 30, 2008 10:51 PM
Anonymous comments are disabled
Page view tracker