Practical Threat Modeling Master Class: STRIDE-Powered

Practical Threat Modeling Master Class: STRIDE-Powered

🎙 Prabh Nair 👥 184K 📅 August 29, 2025 ⏱ 91 min 👁 12K 📄 expert opinion 🧭 2026-08-17
Available in: English (current) Français

Keywords

threat modelingSTRIDEdata flow diagramtrust boundariesrisk assessment

Summary

In this podcast, Prabh Nair interviews Pushpinder Singh, a cloud security architect, on practical threat modeling. They discuss the importance of threat modeling in the software development lifecycle, emphasizing proactive security design. The conversation covers the STRIDE methodology (Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege) and its application to cloud architectures. Key topics include data flow diagrams, trust boundaries, and the integration of threat modeling into DevSecOps. They also explore the differences between STRIDE, PASTA, and DREAD, and introduce MAESTRO for AI systems. The discussion includes a real-world e-commerce example, demonstrating how to apply STRIDE to identify threats and implement mitigations. They highlight the importance of creating living threat model documents and using tools to streamline the process. The session concludes with advice on how to start threat modeling without dedicated tools, emphasizing the need for stakeholder buy-in and iterative refinement.

145 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable insights into practical threat modeling, drawing on the speaker’s real-world experience. The argumentation is solid, with clear explanations of concepts and their application. The discussion on the importance of data flows and the need for ‘just enough security’ is particularly compelling. The use of an e-commerce example helps illustrate the methodology in a tangible way. However, some claims lack empirical evidence, and the argumentation is primarily based on anecdotal experience rather than formal research.

87 words

Title / Content Match

The title accurately reflects the content, which is a practical master class on threat modeling using STRIDE.

Quality & Reliability

8/10

The video is an expert-led discussion with practical insights, but lacks formal citations and rigorous verification of claims.

Chapters

Cited Sources

Concurring Sources

Dissenting Sources

  • PASTA threat modeling — The video suggests STRIDE is more structured, but PASTA is also a comprehensive methodology; some practitioners argue PASTA provides a more risk-centric approach.

Contribution & Novelties

The video offers a practical, experience-based perspective on threat modeling, emphasizing the importance of integrating security early in the development lifecycle. It provides a clear explanation of STRIDE and its application to cloud architectures, with a real-world e-commerce example. The discussion on adapting threat modeling to AI systems via MAESTRO is a notable addition. The emphasis on creating living documents and using tools to streamline the process is valuable for practitioners.

Pour aller plus loin :

123 words

Radar Profile

The radar profile shows high scores in information quantity and quality, with moderate technical depth and reliability. This indicates a well-rounded, informative video that balances practical advice with theoretical grounding, though it could benefit from more rigorous sourcing.

Reliability 7/10

💬 No comments provided.