Published: 30 May 2024
Summary
As the responsibility for application security is increasingly shared, security and risk management leaders question how to scale programs and foster collaboration with stakeholders. This research offers best practices to use threat modeling as a long-term risk reduction tool for security-by-design programs.
Included in Full Research
Overview
Key Findings
Development teams are confused about when they should draft, updateor amend threat models, which are critical to many security-by-design programs.
Although accurate threat modeling can be performed with manual processes, it can be difficult to ensure all relevant areas are mapped sufficiently. This can often lead to the process being avoided by teams when not given adequate direction.
While practicing DevSecOps, development teams often overcomplicate threat modeling exercises by fully modeling similar applications.
Threat modeling is a time-intensive exercise, especially when creating new models from scratch, resulting in greater workload, tighter deadlines and teams forgoing effort.
Recommendations
Security and risk management (SRM) leaders
Clients can log in to view the entire
document.