<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.msdn.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Welcome to the SDL Blog!</title><link>http://blogs.msdn.com/sdl/archive/2007/04/26/welcome-to-the-sdl-blog.aspx</link><description>Greetings and welcome to the Microsoft Security Development Lifecycle Blog! We on the Security Engineering team at Microsoft have been getting a lot of friendly pokes from customers, partners, colleagues, and competitors, asking us to say more about the</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: Welcome to the SDL Blog!</title><link>http://blogs.msdn.com/sdl/archive/2007/04/26/welcome-to-the-sdl-blog.aspx#2629236</link><pubDate>Mon, 14 May 2007 20:21:41 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:2629236</guid><dc:creator>NatureBuff</dc:creator><description>&lt;p&gt;I like what I see so far.&lt;/p&gt;</description></item><item><title>on threat modelling</title><link>http://blogs.msdn.com/sdl/archive/2007/04/26/welcome-to-the-sdl-blog.aspx#2653854</link><pubDate>Tue, 15 May 2007 21:19:36 GMT</pubDate><guid isPermaLink="false">91d46819-8472-40ad-a661-2c78acb4018c:2653854</guid><dc:creator>vc-programmer</dc:creator><description>&lt;p&gt;hi,&lt;/p&gt;
&lt;p&gt;i had a couple of questions on STRIDE modelling, not sure if this is the right place to ask.&lt;/p&gt;
&lt;p&gt;1&amp;gt; STRIDE is defined as &amp;quot;a method of classifying the effect of a threat being realized&amp;quot;.&lt;/p&gt;
&lt;p&gt;(a) since its the &amp;gt;&amp;gt;effects&amp;lt;&amp;lt; of a threat being realized, what are threats then?&lt;/p&gt;
&lt;p&gt;(b) effects of a threat being realized is &amp;gt;&amp;gt;risk&amp;lt;&amp;lt;.&lt;/p&gt;
&lt;p&gt;2&amp;gt; Since STRIDE is listed as a method for threat modelling, where are threats coming into the picture, if at all?&lt;/p&gt;
&lt;p&gt;could you share whats your understanding about STRIDE...&lt;/p&gt;
&lt;p&gt;thanks&lt;/p&gt;
</description></item></channel></rss>