PASTA Threat Modeling for Cybersecurity | OWASP All Chapters 2020 Presentation

Поділитися
Вставка
  • Опубліковано 10 січ 2025

КОМЕНТАРІ • 20

  • @1-P3RSP3CT1VE
    @1-P3RSP3CT1VE 10 місяців тому +1

    Clear and comprehensive insight into PASTA. Greatly appreciated! Ty 👍

  • @Papabuonair
    @Papabuonair 4 роки тому +2

    Thanks! very good ideas!

  • @null-mk4zs
    @null-mk4zs 2 роки тому +2

    Hi,VerSprite.I have whatched you full video,and thank you so much for sharing this video! I wanna know if I could make a DFD diagram for a workflow which involves kinds of solftware,and then creating a Threat Model? I am looking foward to your answer~Thanks so much!

    • @VerSprite
      @VerSprite  2 роки тому +1

      Yes, DFD is one of the most important steps in Stage 3 PASTA threat modeling. The processing of DFD information will help you better understand the inputs, the outputs, and the many actions in between. We also have a blog on our website that does a deeper dive into PASTA. Feel free to skip to stage 3 for more info on DFD: versprite.com/blog/what-is-pasta-threat-modeling/

    • @tonyuv5062
      @tonyuv5062 Рік тому

      You can use PASTA to do an org threat model vs. an app threat model and process decomposition is stage 3 of org threat modeling. You can determine if the workflow around software development bears any weaknesses that could be altered by a threat actor to any entity executing on those workflows. Helpful when trying to take that PFD (Process Flow Diagram) to see where abuse cases could be unleashed to affect code quality, code integrity, affect downstream build processes and more.

  • @_tube7362
    @_tube7362 2 роки тому +1

    very good presentation, can we do a single experiment or is it a free source to use it.

    • @VerSprite
      @VerSprite  2 роки тому

      ቅያ_Tube, thank you for watching.
      Here is a link to the PASTA ebook for reference. versprite.com/ebooks/leveraging-risk-centric-threat-models-for-integrated-risk-management/
      Please feel free to use PASTA in your organizational threat modeling.
      If you need further assistance or just want to chat please feel free to contact us anytime.
      versprite.com/contact/

  • @afrahfathima8866
    @afrahfathima8866 2 роки тому +1

    very iinformative video

  • @satyajitdas435
    @satyajitdas435 2 роки тому

    Informative !!

  • @Phonehangers
    @Phonehangers 3 роки тому

    Hey brother can you build threat model for an erp app

  • @sundayawo8767
    @sundayawo8767 2 роки тому +1

    hey i have a class assignment on threat modelling,can you help me out?pls lets talk about it

    • @VerSprite
      @VerSprite  2 роки тому

      Hello Sunday, thank you for reaching out. We have a lot of helpful threat modeling resources on our website.
      For example here is a RACI Diagram that shows the roll distrubition during each step of the threat model.
      versprite.com/blog/application-security/threat-modeling/versprite-pasta-threat-modeling-raci-diagram/

    • @VerSprite
      @VerSprite  2 роки тому

      Here is a link to the PASTA threat modeling ebook for reference.
      versprite.com/ebooks/leveraging-risk-centric-threat-models-for-integrated-risk-management/

  • @kevinfleming8571
    @kevinfleming8571 4 роки тому +12

    You just blew your credibility by saying that STRIDE is useless. Clearly you're way too biased and can't play nice with the other kids. Bye

    • @maciekstrzelecki8686
      @maciekstrzelecki8686 3 роки тому +3

      Dont let the door hit you on the way out! ;-)

    • @tonyuv5062
      @tonyuv5062 Рік тому +1

      I guess I like to be wrong. It's 2023 and using an immutable threat categorization from over 20 years ago is still useful in a world of extortion, persistence, cryptojacking that doesn't align to any of those 6 buckets. 🤡

  • @snaz738
    @snaz738 2 роки тому

    please contact me for the assistance of threat modeling using mitre model

    • @VerSprite
      @VerSprite  2 роки тому

      Hi S Naz, would love to discuss this in further detail. Please provide me with your email address, or simply go to our contact page and fill out the form (versprite.com/contact/). Looking forward to connecting with you.

    • @afrahfathima8866
      @afrahfathima8866 2 роки тому +1

      need some help regarding Threat modeling

    • @VerSprite
      @VerSprite  2 роки тому

      Hi@@afrahfathima8866would love to connect and help you with your Threat Model.
      Please provide your email address, or simply go to our contact page and fill out the form (versprite.com/contact/).
      Looking forward to helping you.