Threat actors are constantly evolving their tactics, techniques, and procedures (TTPs), which often makes understanding and mitigating potential threats a daunting task. Traditional threat modeling frameworks can fall short or even be seen as intimidating to defenders trying to model potential threats. This is often due to the complexity or amount of effort and knowledge … [Read more...] about Threat modeling: As easy as OATMEAL
Modeling
Introducing the Open Supply-Chain Information Modeling (OSIM) Technical Committee
Supply chain security has emerged as a critical concern for businesses in every sector. The importance of standardized, trustworthy, and interoperable information models cannot be overstated. Addressing this need, the OASIS Open Supply Chain Information Modeling (OSIM) Technical Committee (TC) is being formed to enhance supply chain management worldwide. The initial TC members … [Read more...] about Introducing the Open Supply-Chain Information Modeling (OSIM) Technical Committee
The Need for Continuous and Dynamic Threat Modeling
This blog is co-authored by Mohammad Iqbal and is part four of a four-part series about DevSecOps. The trend towards accelerated application development, and regular updates to an architecture through an agile methodology, reduces the efficacy and effectiveness of point-in-time threat modeling. This recognition led us to explore and strategize ways to continuously, and … [Read more...] about The Need for Continuous and Dynamic Threat Modeling