Next Steps

27 views
Skip to first unread message

Anurag Agarwal

unread,
May 27, 2011, 12:45:38 PM5/27/11
to owasp-thre...@googlegroups.com
Guys- Tony did a great presentation today and I wish we had more
participation but I understand people are busy.

Moving forward, we will communicate over the email so people can respond
when they have time. Here are the next steps

Step 1 - Components of a threat model and aligning it to existing resources.
John has already created a glossary and I am sure people have looked at it.
I am going to send an email out on this shortly and I encourage you all to
chip in with your 2 cents.

Step 2 - Define the step by step process, actors, input/output points and
deliverables at the end of each process. Tony has sent a ppt to the group
which he presented today. Please refer to slide 8.This is going to be our
starting point. We will discuss it in more details going forward.

Step 3 - Metrics. It would be a great idea to show the value of threat
modeling process through the metrics. Tony covered this slightly on slide 4
of the ppt. We need to discuss it further and finalize on what kind of
metrics should be created and at what stage, etc.

Step 4 - How tos, templates, etc.

Please let me know if I missed anything.

Thanks,

Anurag Agarwal
MyAppSecurity Inc
Cell - 919-244-0803
Email - anu...@myappsecurity.com
Website - http://www.myappsecurity.com
Blog - http://myappsecurity.blogspot.com
LinkedIn - http://www.linkedin.com/in/myappsecurity

Seba

unread,
Jul 15, 2011, 4:41:12 AM7/15/11
to OWASP Threat Modeling
Any timings / people assigned to these next steps?

--Seba

Anurag Agarwal

unread,
Jul 29, 2011, 11:47:37 PM7/29/11
to owasp-thre...@googlegroups.com
Guys - I am assuming some of you guys are going to be at BlackHat but I
wanted to reignite this conversation. As mentioned in the email below there
are 4 steps. I want to start with Step 1-3 and see who would like to work on
these steps. We can do it individually or as a group and then present it to
the entire group here.

Step 1 - Identify components of a threat model
Step 2 - Define step by step process, actors, activities, output of each
step
Step 3 - Metrics

Any takers for any of these activities?

Tony's slides are attached.

Thanks,

Anurag Agarwal
MyAppSecurity Inc
Cell - 919-244-0803
Email - anu...@myappsecurity.com

OWASP_TM_Meth_Proposal.ppt

Anurag Agarwal

unread,
Aug 8, 2011, 9:45:30 AM8/8/11
to owasp-thre...@googlegroups.com
Hi Guys - I hope everybody is back from BH/DC/BSides and may have some time
to spare on these activities. Please let me know if one or more of you would
like to work on a specific activity. (See below for details)

Venkatesh Jagannathan

unread,
Sep 9, 2011, 4:09:09 AM9/9/11
to owasp-thre...@googlegroups.com
Hi Anurag et al,
    Any updates here?
 
Thanks & Regards,
~Venki

Venkatesh Jagannathan

unread,
Oct 11, 2011, 9:58:18 AM10/11/11
to owasp-thre...@googlegroups.com, sebastien.d...@gmail.com, anurag....@yahoo.com
Hi,
Any updates here folks?

Anurag Agarwal

unread,
Nov 10, 2012, 12:29:25 PM11/10/12
to owasp-thre...@googlegroups.com

Meeting minutes from our meeting on 11/10/12

 

1. We will identify all the threat modeling resources on owasp and google group and put them under owasp threat modeling wiki page.

2. Review and finalize the glossary for threat modeling

 

Next meeting is on 11/17 @noon EST on skype.

Agenda : High level bullet points for the owasp threat modeling methodology

 

Thanks,

 

Anurag Agarwal

MyAppSecurity

Seba

unread,
Nov 11, 2012, 3:47:23 AM11/11/12
to owasp-thre...@googlegroups.com
thx for the update.
Keep up the good work!

--seba

Reef DSouza

unread,
Nov 13, 2012, 4:14:05 PM11/13/12
to owasp-thre...@googlegroups.com
Hey,

I've compiled a list of resources on threat modeling based on information available on the OWASP site and other sources on the internet. You'll find it in the documents attached. We will carry out the discussion and make the changes to the wiki later in the week. Please share any other resources you might have and submit your comments / feedback.

Thanks,

Reef
Online Threat Modeling Resources.docx
OWASP Threat Modeling Resources.docx
Reply all
Reply to author
Forward
0 new messages