{"id":38491,"date":"2022-07-07T07:15:00","date_gmt":"2022-07-07T07:15:00","guid":{"rendered":"https:\/\/cloudnewshub.com\/archives\/38491"},"modified":"2022-07-07T07:15:00","modified_gmt":"2022-07-07T07:15:00","slug":"the-evolution-of-threat-modelling-as-a-devsecops-practice","status":"publish","type":"post","link":"https:\/\/cloudnewshub.com\/?p=38491","title":{"rendered":"The evolution of threat modelling as a DevSecOps practice"},"content":{"rendered":"<div><img decoding=\"async\" src=\"http:\/\/cloudnewshub.com\/wp-content\/uploads\/2022\/07\/the-evolution-of-threat-modelling-as-a-devsecops-practice.png\" class=\"ff-og-image-inserted\"><\/div>\n<p><a href=\"https:\/\/www.techtarget.com\/searchsecurity\/definition\/threat-modeling\">Threat modelling<\/a> is the process of visualising vulnerabilities in software from the design phase through the software development lifecycle. A relatively new software security practice, it has gathered significant traction over the past few years.<\/p>\n<p>Historically, threat modelling was \u2013 literally \u2013 conducted by security professionals using whiteboards. Today, though, it\u2019s becoming more integrated into software architecture design, with developers increasingly able to take it on in collaboration with the security team, <a href=\"https:\/\/www.techtarget.com\/searchitoperations\/tip\/Threat-modeling-and-DevOps-A-partnership-in-the-making\">complementing the DevSecOps model<\/a>.<\/p>\n<p>And it\u2019s continuing to evolve. Open source threat modelling is arguably the next step, with tool agnosticism meaning it can be much more widely adopted.<\/p>\n<p>The practice of examining the design of a software system to identify potential security problems, the ultimate purpose of threat modelling is to anticipate \u2013 and proactively address \u2013 how an attacker might compromise an application.<\/p>\n<p>Fundamentally, it involves answering the following questions during the design phase. What are we building? What can go wrong? What are we going to do about it? And did we do a good job?<\/p>\n<p>By finding vulnerabilities in this way early in the software development lifecycle, developers can build protections into the code from the start, thereby saving considerable time and money on tackling any security breaches that occur further down the line.<\/p>\n<p>Any threat model built during this early stage should then be used to inform all downstream security activities, including implementation, testing and beyond. In many cases, however, the model is only used during the design phase, becoming less relevant as the project progresses.<\/p>\n<section class=\"section main-article-chapter\" data-menu-title=\"Shift left\">\n<h3 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"><\/i>Shift left<\/h3>\n<p>But, by embracing threat modelling, developers can build valuable relationships with their organisation\u2019s security team. Such relationships are ever more important with security joining the \u201cshift left\u201d movement and becoming an increasingly essential part of the application build pipeline \u2013 development and security teams need to work closely together to create repeatable processes that result in secure software.<\/p>\n<p>This, then, is DevSecOps, an extension of the DevOps model in which security has a seat at the table through every phase of the DevOps process. And, given that it\u2019s inherently a collaborative activity involving the security and development teams, threat modelling closely lends itself to this model. In fact, the iterative nature of the threat modelling methodology fits the DevOps process well. Each time a new \u201cplan\u201d phase is reached, for instance, there is an opportunity for threat modelling. Then, with each new sprint or iteration, that threat model can be further reviewed and revised.<\/p>\n<p>With its importance as part of the DevSecOps model now recognised, it\u2019s likely that the evolution of threat modelling will soon see the practice becoming more widely adopted.<\/p>\n<\/section>\n<section class=\"section main-article-chapter\" data-menu-title=\"Accessible to all\">\n<h3 class=\"section-title\"><i class=\"icon\" data-icon=\"1\"><\/i>Accessible to all<\/h3>\n<p>At its most basic, threat modelling can be carried out by experts and engineers using a whiteboard.<\/p>\n<p>Over time, though, software development has become increasingly about moving fast with a culture of continuous integration and deployment. This, coupled with development teams working on dozens \u2013 or even hundreds \u2013 of services simultaneously means the manual \u201cwhiteboard\u201d method of threat modelling is largely untenable. It\u2019s often not practical and it\u2019s certainly not scalable.<\/p>\n<p>Threat modelling has had to evolve to keep up with the pace and demands of software development. With security now a board-level priority for most organisations, it\u2019s become a critical capability for business leaders. Indeed, it\u2019s now recognised as critical software security practice. In the US, for example, the National Institute for Standards and Technology recommends that threat modelling is undertaken as part of its <a href=\"https:\/\/www.nist.gov\/itl\/executive-order-improving-nations-cybersecurity\/recommended-minimum-standard-vendor-or-developer\">Recommended Minimum Standards for Vendor or Developer Verification of Code<\/a>.<\/p>\n<p>Until recently, threat modelling was still primarily the domain of an organisation\u2019s security experts. Now though, the advent of open source tools \u2013 the next logical step in threat modelling\u2019s evolution \u2013 means it is accessible to developers, too \u2013 essential as part of the DevSecOps model.<\/p>\n<p>There are offerings currently available in the market which are designed to be used by security teams and developers, and contain templates, pre-defined databases of common threats and easy-to-use dashboards, as well as the ability to gather threat intelligence from open global libraries.<\/p>\n<p>Threat modelling has come a long way from the manual whiteboard approach. Open source tools are set to transform the threat modelling process. By making it an increasingly simple and widely adopted practice, they will have a significant impact on secure design. As the delivery pipeline becomes faster and more complicated, and as the threat landscape continues to grow in its sophistication, the benefits of open source threat modelling tools in enabling an effective DevSecOps approach represent a huge step towards achieving true secure software design.<\/p>\n<p><em>Stephen de Vries is co-founder and CEO of <a href=\"https:\/\/www.iriusrisk.com\/\">IriusRisk<\/a><\/em><\/p>\n<\/section>\n","protected":false},"excerpt":{"rendered":"<p>Threat modelling is the process of visualising vulnerabilities in software from the design phase through the software development lifecycle. A relatively new software security practice, it has gathered significant traction over the past few years. Historically, threat modelling was \u2013 literally \u2013 conducted by security professionals using whiteboards. Today, though, it\u2019s becoming more integrated into [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":38492,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[533],"tags":[],"class_list":["post-38491","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-it"],"_links":{"self":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/38491","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=38491"}],"version-history":[{"count":0,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/posts\/38491\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=\/wp\/v2\/media\/38492"}],"wp:attachment":[{"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=38491"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=38491"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cloudnewshub.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=38491"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}