logo

Threat modeling and the supply chain: An essential tool for managing risk across the SDLC

ID: fff0f172-7d05-5d1b-be35-666427cd3930

STIX ID: report--fff0f172-7d05-5d1b-be35-666427cd3930

Feed Name: ReversingLabs Blog

Date Published: 2023-09-21

Date Updated: 2026-04-29

Author: [email protected] (Ericka Chickowski)

...
...

This article presents 10 practical tips for building an enterprise threat modeling program, including choosing a scalable process (scope, draw, analyze, mitigate, document), embracing STRIDE, embedding threat modeling into the SDL and daily tooling, prioritizing mitigations and measurable outcomes, instituting quality checks and governance, cultivating diverse champions and coaches, teaching via workshops, broadening threat sources (OWASP ASVS, CWE), and fostering a mindset that values principles over tools to scale threat modeling across the organization.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.