article thumbnail

Review: Practical Cybersecurity Architecture

Adam Shostack

Adam Shostack's review of the book Practical Cybersecurity Architecture There's an insightful comment , "Everybody has a testing environment. Similarly, everybody has both enterprise and product architecture. Importantly, the book is short, readable and grounded, and I've learned a lot reading it.

article thumbnail

Review: Practical Security Architecture

Adam Shostack

” Similarly, everybody has both enterprise and product architecture. I have to say that because “architecture” is much maligned for being heavyweight, disconnected, and irrelevant in today’s world of Dev-Opsy CI/CD moving fast and breaking things. They say nice things about my Threat Modeling book.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Hoarding, Debt and Threat Modeling

Adam Shostack

Maybe one person thinks a good dusting is enough; another that things need to be in containers (books on shelves, desk clutter in baskets, papers in files) and yet another thinks that without bleach, its a waste. On the other side is a whiteboard with a software architecture diagram Some thoughts: Define clean. No new problems.

article thumbnail

Threat Modeling Gameplay with Eop

Adam Shostack

You should get the Threat Modeling Gameplay book, now available! Thats why Im so pleased that Brett Crawley has written a book, Threat Modeling Gameplay with EoP: A reference manual for spotting threats in software architecture.

article thumbnail

News alert: Seraphic launches BrowserTotal™ — a free AI-powered tool to stress test browser security

The Last Watchdog

Users can book a demo time in advance here. Seraphic delivers SWG, CASB, and ZTNA to simplify existing security architectures and significantly reduce SSE cost. .” Attendees of the Gartner Security & Risk Management Summit 2025 can experience Browser Total firsthand at booth #1257.

Marketing 130
article thumbnail

Appsec Roundup - September 2024

Adam Shostack

Michael Nygard has a nice write up on using Architecture Decision Records in Documenting Architecture Decisions that I hadnt seen before. Shostack + Associates updates Adam will be doing a book signing at the Pheonix Security booth at OWASP Global Appsec San Francisco on Friday the 27th at 3PM.

article thumbnail

Building a Ransomware Resilient Architecture

eSecurity Planet

While security teams layer essential preventative measures, resilience measures also need to be implemented in an architecture to reduce the impact of ransomware attacks on your backups. Figure 1: Typical VLAN architecture. Figure 2: Resilient VLAN architecture. How could this have been prevented? Does this add latency?