Keynote - Get Out of your Bubble: Collaborative Threat Modeling by Avi Douglen
09:15 - 10:00
Abstract:
Threat modeling by yourself is great - noone is there to tell you you're wrong. But if you want to discover nontrivial issues that you don't have on your checklist, you'll need to engage with others. Too often, though, we chase them away. One of the biggest traps is falling down a rabbit hole of technical details, without involving other stakeholders or considering their perspectives. This lack of context creates an inaccurate model of the system, misguided threats, and inefficient investment of security effort.
In this keynote, we will look at ways to make security more social and lightweight - how to productively engage with teammates, challenge your own assumptions, and drive actionable, high-value outcomes that make AppSec truly collaborative.
Bio:
Avi Douglen has been building secure applications for decades, and is *obsessed* with maximizing value output from security efforts. Avi is the founder and CEO of Bounce Security, a boutique consulting agency dedicated to helping product developers integrate security efficiently into their workflows. He is a frequent speaker and trainer, and has trained thousands of developers to build more secure products. AviD is a current member of the OWASP Global Board of Directors and was the previous Chair of the Board. He also leads the OWASP Israel chapter, created the popular AppSecIL security conference, and co-founded the OWASP Application Privacy project. He also co-authored the Threat Modeling Manifesto.