--- title: "Adam Shostack – Threat Modeling – 5 Minute AppSec" url: https://appsecpodcast.com/adam-shostack-threat-modeling-5-minute-appsec/ date: 2019-07-09 duration_seconds: 115 guests: ["Adam Shostack"] topics: ["Threat Modeling"] audio: https://www.buzzsprout.com/1730684/episodes/8122639-adam-shostack-threat-modeling-5-minute-appsec.mp3 transcript: true --- # Adam Shostack – Threat Modeling – 5 Minute AppSec *July 9, 2019 · 2 min* with [Adam Shostack](https://appsecpodcast.com/guests/adam-shostack/) on [Threat Modeling](https://appsecpodcast.com/topics/threat-modeling/) [Audio](https://www.buzzsprout.com/1730684/episodes/8122639-adam-shostack-threat-modeling-5-minute-appsec.mp3) ## Show notes Why threat model when AppSec teams already have scanners, checklists, and testing? Adam Shostack argues that threat modeling is what makes those activities structured, systematic, and comprehensive instead of a collection of guesses. In this rapid 5 Minute AppSec, he explains how asking what you are building and what can go wrong focuses attention on the right parts of a system. Approaches such as STRIDE, attack trees, and kill chains help teams examine each element methodically, then use the results to guide the rest of the security program. Skip that step, Adam warns, and you are shooting in the dark. Stay through the end for a candid recording outtake. Connect with Adam Shostack: → [Adam Shostack on LinkedIn](https://www.linkedin.com/in/shostack) → [Shostack + Associates](https://shostack.org/) Mentioned in this episode: → [Adam Shostack](https://shostack.org/) → [Attack Trees (Schneier)](https://www.schneier.com/academic/archives/1999/12/attack_trees.html) → [Cyber Kill Chain (Lockheed Martin)](https://www.lockheedmartin.com/en-us/capabilities/cyber/cyber-kill-chain.html) Chapters: 00:00 Why threat model? 00:10 Structured, systematic, and comprehensive security 01:07 The promised full interview 01:33 A candid recording outtake ## Transcript *269 words · assemblyai* **0:00 Chris Romeo:** If you've done anything with threat modeling, you've heard of Adam Shostack. And on this 5 Minute AppSec, we asked Adam a very simple question: why would anybody ever threat model? **0:10 Adam Shostack:** You know, it's a great question. Threat modeling is fundamentally the best way to make sure that your security activities are structured, systematic and comprehensive. **0:22 Adam Shostack:** By asking, what are we working on? You can make sure that the things that you're working on are getting considered. **0:32 Adam Shostack:** By using a structured approach to asking what can go wrong, like STRIDE or attack trees or a kill chain, you can systematically go through each of the elements of your system to make sure that you've thought about security. And that can inform the entire remainder of your AppSec program and activities. **1:01 Adam Shostack:** If you don't threat model, you're shooting in the dark and hoping to hit the right things. **1:07 Chris Romeo:** Stay tuned for our next episode where you'll hear the full interview we did with Adam on the topic of threat modeling layer 8, or looking at threat modeling from the human problem perspective. And if you ever wonder what happens behind the scenes here at the Application Security Podcast, continue listening for our first attempt at recording this 5 Minute AppSec. So Adam, why do we need threat modeling? **1:33** You know, I don't even know. Sorry, I just had to give you that. You want to do it again? **1:45 Chris Romeo:** Yeah, I'm putting that— it's going to be the shortest 5 Minute AppSec of all time. It's gonna be like one sentence. And I was like, nah, I don't really know why. --- Source: https://appsecpodcast.com/adam-shostack-threat-modeling-5-minute-appsec/