Rethinking Secure DevOps Threat Modeling: The Need for a Dual Velocity Approach
Altaz Valani · 2018
Today's business models compete on achieving speed of delivery to end customers. To support this, development teams emphasize automation and Secure DevOps as key enablers. The challenge is maintaining speed to support business needs when security activities like threat modeling require highly skilled individuals and detailed analysis. Conducting threat modeling on a per application basis for each iteration is too slow. For example, there are challenges with initial creation of data flow diagrams. Furthermore, application changes might occur several times a day which makes ongoing creation of data flow diagrams onerous. We propose use of a lightweight threat modeling approach which uses a correlation matrix created from common lists and application abstractions. The result is a lightweight threat modeling approach which is quicker and addresses many use cases where a detailed threat modeling approach is not necessary. Traditional data flow threat modeling can still be used for special cases thereby creating a dual velocity approach. From our experience with large organizations, this dual velocity approach lends itself better to scaling threat modeling, automation, and traceability in Secure DevOps.