The programme is a blend of practical use cases based on real-world projects and mentoring. Each use case includes an environmental description, questions, and templates for building a threat model.Participants are challenged in virtual [...]
  • QATORTMP-QA
  • Cena na vyžádání

The programme is a blend of practical use cases based on real-world projects and mentoring. Each use case includes an environmental description, questions, and templates for building a threat model.Participants are challenged in virtual breakout rooms to carry out the different stages of threat modelling on the following:Diagramming web and mobile applications, sharing the same REST backendThreat modelling an IoT gateway with a cloud-based update serviceGet into the attacker’s head – modelling points of attack against a CNI facilityThreat mitigations for microservices and S3 buckets in a payment serviceThreat modelling the CI/CD pipelineThe results are discussed after each hands-on workshop, and participants receive a documented solution.

  • The why, what, how, and when of threat modelling
  • How to create and update a threat model
  • How to create an actionable threat model with your stakeholders
  • How to organise and prepare efficient threat modelling workshops
  • How to explain the methodology and need for threat modelling to others
  • Diagramming techniques, including Data Flow Diagramming
  • Threat identification techniques, including STRIDE and attack trees
  • How to carry out technical risk rating using the OWASP risk rating methodology
  • How to mitigate security and privacy threats with standard mitigations
  • The soft skills that will make you a better threat modeler

Mám zájem o vybraný QA kurz