Threat modelling
Security & software supply chain
Threat modelling
Threat modelling examines assets, entry points, and possible abuse. Ask four questions: what are we working on, what can go wrong, what will we do about it, and did we do a good job? STRIDE helps you list threats.
Resources
Links marked “Amazon affiliate link” open an Amazon product page. As an Amazon Associate I earn from qualifying purchases. About affiliate links
Threat Modeling: Designing for SecurityBook · Adam Shostack · Amazon affiliate link, opens Amazon in a new tabThreat Modeling ManifestoReference · Threat Modeling Manifesto working group · opens in a new tabAlice and Bob Learn Application SecurityBook · Tanya Janca · Amazon affiliate link, opens Amazon in a new tabDevOps guides (in French)Blog · Stéphane Robert · opens in a new tabOWASP Cheat Sheet SeriesReference · OWASP · opens in a new tabSecuring DevOpsBook · Julien Vehent · Amazon affiliate link, opens Amazon in a new tabDeveloping Secure Software (LFD121)Course · OpenSSF, The Linux Foundation · opens in a new tab