Using Threat Modeling to Create a DevSecOps plan

June 29, 2024
1:35 PM
Stage 2
Hands-on workshop

About this session

Learn how to use threat models as a guide for creating a plan to select, implement, and configure the right security tools to cover the mitigations identified in the threat model and embed these tools in the right places in the SDLC. Starting with a sample service and its Threat model, we'll explore different types of mitigations (e.g business logic/code mitigations, use of library/tools mitigations, configuration mitigations, and process mitigations) and delve into some security tools used to test those mitigations.

About the speaker

Currently a Staff Application Security engineer at IronClad with the role of building a new AppSec Program. Before that, Mohamed was also an AppSec Engineer at Amazon for ~ 4 years where he collaborated on 500+ AWS services/features/tools.

Speaker

Speakers

Mohamed AboElKheir
Staff Application Security Engineer, IronClad