Certified Threat Modeling Professional (CTMP)

I. Overview:

The Certified Threat Modeling Professional (CTMP) is first of its kind Vendor-neutral threat modeling training and certification Program.

This course is targeted towards individuals or teams interested in devoting their careers to learning and implementing industry security best practices around Threat modeling.

II. Duration:  40 hours
III. Objectives:

Upon completion of this Threat Modeling training course, you will be able to understand:

  • Basics of Threat modeling from a business perspective.
  • Major components in Agile Threat Modeling
  • How to create and maintain Threat Modeling practice.
  • Creating and maintaining threat models.
  • Facilitating threat modeling sessions with a larger audience
IV. Prerequisites:
  • Course participants should have knowledge of basic security fundamentals like Confidentiality, Integrity, and Availability (CIA)
  • Basic knowledge of application development is preferred but is not necessary
V. Course outlines:

1. Module 1: Threat Modeling Overview

  • What is Threat Modeling?
  • The Threat Model Parlance
    • Security is a Balancing Act
    • Design Flaws and Risk Rating
  • Why Threat Model?
  • Threat Modeling vs. Other Security Practices
  • Threat Modeling Frameworks and Methodologies
    • List/Library Centric Threat Modeling
    • Asset/Goal Centric Threat Modeling
    • Threat Actor/Attacker Centric Threat Modeling
    • Software Centric Threat Modeling
  • Trust Boundaries vs. Attack Surfaces
  • Modern Threat Modeling Approaches for Agile and DevOps
  • Risk Management Strategies with Examples
    • Avoiding Risks
    • Accepting Risks
    • Mitigating Risks
    • Transferring Risks
  • Hands-on Exercises:
    • Breakout Sessions to Identify Threats for a Multi-Tiered Application

2. Module 2: Threat Modeling Basics

  • Threat Modeling and Security Requirements
  • Threat Modeling vs Threat Rating
  • Diagramming for Threat Modeling
  • List Centric Threat Modeling
  • Exploring the STRIDE Model
    • Spoofing
    • Tampering
    • Repudiation
    • Information Disclosure
    • Denial of Service
    • Elevation of Privileges
  • Pros and Cons of STRIDE
  • STRIDE defenses
    • Authentication
    • Integrity
    • Non-Repudiation
    • Confidentiality
    • Availability
    • Authorization
  • STRIDE Threat examples
  • Goal/Asset Based modeling Approach
    • Attack Trees
    • Attack Tree Analysis
  • Attacker/Threat Actor Centric Modeling Approach
    • Using MITRE ATT&CK for Attacker Centric Threat Modeling
  • Software Centric Threat Modeling 
  • Other Threat modeling methodologies
    • PASTA
    • VAST
    • Hybrid Threat modeling
    • RTMP
    • OCTAVE
  • Gamified approaches for Threat Modelling
    • Virtual Card Games
    • Adversary Card Games
  • Introduction to Threat Rating
    • DREAD
    • OWASP Risk Rating Methodology
    • Bug Bar
    • Rapid Risk Assessment
  • Hands-on Exercises:
    • Creating a Data Flow Diagram for Threat Modeling
    • Using OWASP Cornucopia to Identity Web Related Threats
    • Creating Threat Actor Personas
    • Using Threat Actor Personas to Identify Threats
    • Risk Rating with OWASP Risk Rating Methodology

3. Module 3: Agile Threat Modeling

  • Agile Threat Modeling Approaches
    • Threat Modeling Diagrams as Code
    • Threat Modeling Inside The Code
    • Threat Modeling as Code
    • Compliance and Audit as Code
    • Rapid Threat Model Prototyping
  • Security Requirements as Code With BDD Security
  • Events of Agile Software Development Through Scrum
  • Writing Security Requirements for Agile Software Development
  • Writing Use Cases and Abuse Cases
  • Privacy Impact Assessments and Security Requirements
  • Identifying Privacy Related Threats
  • Hands-on Exercises:
    • Writing Abuse Cases for Password Reset Workflow
    • Threat Modeling Privacy for your system
    • Exploring UML as Code
    • Creating Attack Trees Using Code
    • Writing Threat Models Alongside Code
    • Writing Threat Models With Code
    • Writing Threat Models As Code
    • Writing Compliance As Code for PCI-DSS

4. Module 4: Reporting and Deliverables

  • How To Manage Threat Models
    • Documentation
    • Backlog
    • Bugs, and Tickets
    • Code
    • Automation
  • Threat Modeling Tools and Templates
    • Microsoft Threat Modeling Tool
    • OWASP Threat Dragon
    • CAIRIS Platform
    • Threat Modeling As Code Tools
    • Freemium Tools
    • Threat Model Templates and Examples
  • Validating Threat Models
    • Threat Model Versus Reality
    • All Threats Accounted For Risk
    • Mitigations Are Tested
    • Are We Done Threat Modeling?
  • Hands-on Exercises:
    • Threat Modeling with OWASP Threat Dragon
    • Threat Modeling Multi-Tiered Application with Irius Risk
    • Threat Modeling for Multi-Cloud with Irius Risk
    • Validating Threats with Automated Tests
    • Validating Mitigations with Automated Tests

5. Module 5: Secure Design Principles and Threat Modeling Native, and Cloud Native Applications

  • Exploring Principles of Secure Design with Examples
    • Principle of Economy of Mechanism
    • Principle of Fail Safe Defaults
    • Principle of Complete Mediation
    • Principle of Open Design
    • Principle of Separation of Privilege
    • Principle of Least Privilege
    • Principle of Least Common Mechanism
    • Principle of Psychological Acceptability
  • Case Study of AWS S3 Threat model
  • Case Study of Kubernetes Threat Model
  • Case Study of Very Secure FTP daemon

6. CTMP Course Certification Process

  • After completing the course, you can schedule the CTMP exam on your preferred date.


  • Học trực tuyến

  • Học tại Hồ Chí Minh

  • Học tại Hà Nội


Các khóa học khác