<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
		<id>https://wiki.owasp.org/index.php?action=history&amp;feed=atom&amp;title=OWASP_NZ_Day_2020-Training-Security_Uno</id>
		<title>OWASP NZ Day 2020-Training-Security Uno - Revision history</title>
		<link rel="self" type="application/atom+xml" href="https://wiki.owasp.org/index.php?action=history&amp;feed=atom&amp;title=OWASP_NZ_Day_2020-Training-Security_Uno"/>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_NZ_Day_2020-Training-Security_Uno&amp;action=history"/>
		<updated>2026-04-14T07:53:51Z</updated>
		<subtitle>Revision history for this page on the wiki</subtitle>
		<generator>MediaWiki 1.27.2</generator>

	<entry>
		<id>https://wiki.owasp.org/index.php?title=OWASP_NZ_Day_2020-Training-Security_Uno&amp;diff=256442&amp;oldid=prev</id>
		<title>John dileo: Created page with &quot;__NOTOC__  =Security Uno: A Fun Way to Threat Model=  '''Half-Day Interactive Training -- OWASP New Zealand Day 2020'''  == Abstract ==  This course will cover the what, why,...&quot;</title>
		<link rel="alternate" type="text/html" href="https://wiki.owasp.org/index.php?title=OWASP_NZ_Day_2020-Training-Security_Uno&amp;diff=256442&amp;oldid=prev"/>
				<updated>2019-12-18T05:03:04Z</updated>
		
		<summary type="html">&lt;p&gt;Created page with &amp;quot;__NOTOC__  =Security Uno: A Fun Way to Threat Model=  &amp;#039;&amp;#039;&amp;#039;Half-Day Interactive Training -- OWASP New Zealand Day 2020&amp;#039;&amp;#039;&amp;#039;  == Abstract ==  This course will cover the what, why,...&amp;quot;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;__NOTOC__&lt;br /&gt;
&lt;br /&gt;
=Security Uno: A Fun Way to Threat Model=&lt;br /&gt;
&lt;br /&gt;
'''Half-Day Interactive Training -- OWASP New Zealand Day 2020'''&lt;br /&gt;
&lt;br /&gt;
== Abstract ==&lt;br /&gt;
&lt;br /&gt;
This course will cover the what, why, when, and how of threat modelling applications in your organisation. The bulk of this course will be based on the book ''Threat Modeling: Designing for Security'', by Adam Shostack, and will leverage a variant of the ''Elevation of Privilege'' card game - Security Uno - created by the instructor.&lt;br /&gt;
&lt;br /&gt;
== Course Details == &lt;br /&gt;
&lt;br /&gt;
'''Dates:''' Thursday, 20 February 2020&lt;br /&gt;
&lt;br /&gt;
'''Time:''' 1:30 to 5:30 p.m.&lt;br /&gt;
&lt;br /&gt;
'''Course Fee:''' NZ $325.00 (plus EventBrite fees)&lt;br /&gt;
&lt;br /&gt;
'''Registration Site:''' https://owaspnz2020-training.eventbrite.com&lt;br /&gt;
&lt;br /&gt;
'''Attendees Should Bring:''' &lt;br /&gt;
&lt;br /&gt;
* Paper and pen&lt;br /&gt;
* Willingness to learn&lt;br /&gt;
* A laptop, to look at the Serverless Security Goat - which we will attempt to threat model in an exercise&lt;br /&gt;
&lt;br /&gt;
'''Attendees Will Be Provided:'''&lt;br /&gt;
&lt;br /&gt;
* The basics of threat modelling&lt;br /&gt;
* Ways to gain adoption by your peers&lt;br /&gt;
&lt;br /&gt;
'''Instructor:''' Kendra Ash&lt;br /&gt;
&lt;br /&gt;
'''Instructor's Organization:''' [https://www.vacasa.com/ Vacasa]&lt;br /&gt;
&lt;br /&gt;
== Course Objective ==&lt;br /&gt;
&lt;br /&gt;
The objective of this class is to provide the audience with tools to gain adoption for application threat modelling early on in the development pipeline, while also building confidence in how to threat model. &lt;br /&gt;
&lt;br /&gt;
== Course Overview ==&lt;br /&gt;
&lt;br /&gt;
If you are a software, DevOps, QA or security engineer and want to learn how to threat model API’s in AWS this course is for you. This course will cover the what, why, when, and how of threat modeling applications in your organization. The bulk of this course will be based on the book ''[https://www.amazon.com/dp/B00IG71FAS Threat Modeling: Designing for Security],'' by Adam Shostack, and will leverage a variant of the ''[https://www.microsoft.com/en-us/download/details.aspx?id=20303 Elevation of Privilege]'' card game. &lt;br /&gt;
&lt;br /&gt;
I will also dive into the approach I have used, as a Security Engineer, to gain adoption from engineering teams. After gaining an understanding of threat modelling, we will dive into how we can automate security checks for an AWS environment — leveraging the AWS API tool to provide quick engineering feedback on ways to improve the security of their infrastructure. If time allows we will discuss the success with a monthly DevOps report on AWS, GitHub, Incidents, Security and more for each team in the department.&lt;br /&gt;
&lt;br /&gt;
==Your Instructor==&lt;br /&gt;
&lt;br /&gt;
'''Kendra Ash''' - Kendra is a security engineer at Vacasa, actively building a security team and programme by leveraging guidance from her network, and industry standards. She is energetic and cares deeply about safeguarding the end-user's data, through automation, collaboration, and encryption. Outside of work she participates in local meetups, coaches ski racing, and volunteers for her local search and rescue team.&lt;/div&gt;</summary>
		<author><name>John dileo</name></author>	</entry>

	</feed>