The Application Security Podcast

Jason Nelson -- Three Pillars of Threat Modeling Success: Consistency, Repeatability, and Efficacy

• Chris Romeo • Season 11 • Episode 4

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 53:52

Jason Nelson, an accomplished expert in information security management, joins Chris to share insights on establishing successful threat modeling programs in data-intensive industries like finance and healthcare. Jason presents his three main pillars to consider when establishing a threat modeling program: consistency, repeatability, and efficacy. The discussion also provides a series of fascinating insights into security practices, regulatory environments, and the value of a threat modeling champion. As a threat modeling practitioner, Jason provides an essential perspective to anyone serious about application security. Jason Nelson is an information security executive focused on building programs and directing teams in highly regulated financial healthcare and insurance industries.

Connect with Jason Nelson:
→ FINOS Common Cloud Controls
→ NIST OSCAL

Mentioned in this episode:
→ FINOS Common Cloud Controls
→ NIST OSCAL
→ MITRE ATT&CK
→ Malware Analyst's Cookbook
→ Threat Modeling: A Practical Guide for Development Teams
→ Schneier on Security
→ The Security Table (podcast)
→ Start With Why

Follow the Application Security Podcast:
➜ Home
➜ X
➜ LinkedIn
➜ YouTube
➜ Instagram
➜ Facebook

Chapters:
00:00 Introduction
02:13 Security Origin Story
07:48 Threat Modeling the Cloud
16:44 Threat Modeling Pillar One: Consistency
27:30 A Threat Modeling Champion
33:35 Threat Modeling Pillar Two: Repeatability
39:07 Threat Modeling Pillar Three: Efficacy
48:09 Lightning Round

People on this episode

Podcasts we love

Check out these other fine podcasts recommended by us, not an algorithm.

The Security Table Artwork

The Security Table

Izar Tarandach, Matt Coles, and Chris Romeo