mirror of
https://github.com/jackyzha0/quartz.git
synced 2025-12-27 06:44:07 -06:00
vault backup: 2022-10-10 11:12:45
This commit is contained in:
parent
91d508e64e
commit
44fa137253
@ -12,3 +12,56 @@ tags:
|
||||
- built without thinking about security
|
||||
- tests do not take security into account
|
||||
- without security evolution can become cumbersome
|
||||
|
||||
more costly to fix bug in development than in design
|
||||
- the later we fix it the more costly it is
|
||||
|
||||
from the start
|
||||
- hire right people
|
||||
- with hacking mindset
|
||||
- so they alwasys think about security
|
||||
- invite customers to training and seminars
|
||||
- testing could uncover security issues
|
||||
|
||||
questions during feasability
|
||||
- 
|
||||
- what are the implications for users if assets are lost
|
||||
- some information is more high risk that other information
|
||||
|
||||
during design
|
||||
- should be designed in iterative manner
|
||||
- threat modelling
|
||||
- 
|
||||
- Data Flow Diagram (DFD)
|
||||
- 
|
||||
- high or low level
|
||||
- want to be nimble
|
||||
- dont want to go overboard
|
||||
- 
|
||||
-
|
||||
- potential threats
|
||||
- STRIDE
|
||||
- 
|
||||
- can identify parts system using DFD that are threatened by these things
|
||||
- 
|
||||
- 
|
||||
- defines the potential dcisions that are performed by the attacker
|
||||
- 
|
||||
- risk = criticality * likligood of occurance
|
||||
- should be consistent
|
||||
- can also use DREAD
|
||||
- 
|
||||
|
||||
example
|
||||
- 
|
||||
|
||||
responsing to threats
|
||||
- do nothing
|
||||
- inform user
|
||||
- remove problem
|
||||
- fix problem
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
Loading…
Reference in New Issue
Block a user