Understanding and working with threat modeling
In the previous section, we discussed the governance of security in the enterprise and how it's integrated as DevSecOps. In this section, we will learn how security issues can impact the SDLC. When it comes to integrating security in DevOps, you need to have a good understanding of threat modeling, which provides us with information on how security threats may affect how software code is developed and deployed. We'll start by explaining what threat modeling is by looking at the definition of The Open Web Application Security Project (OWASP). OWASP is an online community that provides insights into security threats, tools, and technology.
In essence, a threat model shows how security threats could impact the integrity of an application. The model assembles and analyzes security data and helps in making decisions on how to protect the application, thus improving the security of code and the hosting environment, by assessing...