This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Application Threat Modeling

From OWASP
Revision as of 12:25, 29 May 2008 by EoinKeary (talk | contribs)

Jump to: navigation, search

Introduction

DREAD STRIDE

Identify threats

Understand discovered threats

Threat categorization / Business impact

Data Flow Diagrams

Countermeasures

Assessment

Planning a security assessment or code review based on the threat model deleverable.