Host
Dirk Dussart
BOF Topic
Security Requirements Gathering/Threat Modelling
Developers, designers and architects are more and more faced with security questions and decisions because more and more businesses want their applications to be secure. But what does this mean "to be secure"? Does this mean that we need SSL, crypto algorithms, ... ? In this BOF session we will present the audience with a couple of simple tools they can use to gather security requirements from business and incorporate these requirements in the design through a process of threat modelling. Threat modelling, as described by Howard & LeBlanc (Microsoft) is a process that has drawn inspiration from risk management and applies it to application design.
In this session we will walk you through a small threat modelling exercise.
Target Audience
This track is especially geared towards developers, designers and architects that have to take important security decisions while building security sensitive applications.
Related JavaPolis presentations
Interesting Links