SC_TM 101: Practical Threat Modelling

This class equips students with the knowledge and techniques required to perform a threat model. Threat modeling is a powerful activity to reduce overall cost in application security initiatives by prioritizing threats based on risk. It also allows developers to consider security at the design and architecture phases of the software development life cycle (SDLC).

Threat modeling is gaining traction as a fundamental application security activity. In this class students learn about the attacks that their applications may face and then both formal and informal approaches to threat modeling. Using a fictional scenario, students perform all the activities of a threat model on a complex application - including analyzing design documents and role-playing interviews. Students learn about the industry standard formal threat modeling process as well as Facilitated Application Threat Modeling: a 1-day approach to threat modeling pioneered by Security Compass. Students will also be taught about Security Compass's unique source-code/design-pattern level threat modeling.


For further information please click here for the detailed course outline.


Questions about training? Please contact us at training@securitycompass.com