Learning Threat Modeling for Security Professionals

Go to class
Write Review

Free Online Course: Learning Threat Modeling for Security Professionals provided by LinkedIn Learning is a comprehensive online course, which lasts for Less than 1 hour of material. The course is taught in English and is free of charge. Upon completion of the course, you can receive an e-certificate from LinkedIn Learning. Learning Threat Modeling for Security Professionals is taught by Adam Shostack.

Overview
  • Threat modeling helps security professionals understand what can go wrong—and what to do about it. Learn to use the four-question and STRIDE frameworks for threat modeling.

Syllabus
  • Introduction

    • Develop secure products
    • Why would you threat model?
    • A simple approach to threat modeling
    1. The Four Question Framework
    • What are we working on?
    • What can go wrong?
    • What are we going to do about it?
    • Did we do a good job?
    2. STRIDE
    • Spoofing a specific server
    • Tampering with a file
    • Interlude: Scope and timing
    • Repudiating an order
    • Information disclosure
    • Denial of service
    • Elevation of privilege
    Conclusion
    • Next steps