D4 · Operations

What is rapid threat modeling?

Rapid threat modeling applies quick threat analysis in agile development — answering 4 questions: What are we building? What can go wrong? What are we going to do about it? Did we do a good enough job?
Full threat modeling is sometimes impractical for every sprint. OWASP Cornucopia and Elevation of Privilege are card games that make threat modeling accessible to developers. Any threat modeling is better than none.
← Back to Glossary Practice Questions →