Advanced Threat Modeling and Risk Assessment in DevSecOps

Advanced Threat Modeling and Risk Assessment in DevSecOps

1h 38mIntermediate2025-07-11

Authors

Tino Šokić

Tino Šokić

Course details

This course provides a structured approach to understanding threat modeling principles, risk assessment methodologies, and their application within modern CI/CD pipelines. Aimed at DevSecOps professionals, developers, and security practitioners, the course explores key concepts such as attack surfaces, vulnerabilities, risk scoring models, and the use of threat intelligence to enhance security decision-making. Instructor Tino Šokić covers popular frameworks like MITRE ATT&CK and OWASP Top 10, practical techniques for performing quick risk assessments, and the tools available for managing threat modeling. Check out this course to find out how you can apply continuous threat modeling, communicate risk effectively, and integrate security seamlessly into DevSecOps workflows.

Learning objectives
Integrate threat modeling and security testing into your DevSecOps pipeline, ensuring continuous security validation throughout the software development lifecycle.
Perform systematic risk assessments by evaluating threat likelihood and impact, and develop prioritized mitigation strategies aligned with your organization’s security objectives.
Develop a risk-aware mindset for secure development and promote collaboration between development, security, and operations teams to proactively address risks.
Continuously improve threat modeling and risk management by establishing repeatable, scalable threat modeling practices.

Skills covered

Software Development SecurityDevOps FoundationsDevOpsCybersecurityOne-Off

Concepts

Introduction

  • Threat modeling and risk assessment in devsecops
  • What you should know

Demystifying DevSecOps and Threat Modeling

  • What is DevSecOps
  • What is threat modeling
  • Key concepts in threat modeling - Assets, threats, vulnerabilities, and risks
  • Threat modeling in DevSecOps
  • Threat modeling vs. traditional security assessments

Risk Assessment in DevSecOps

  • Understanding risk in DevSecOps
  • Threats, vulnerabilities, and impact
  • Common risk assessment frameworks
  • How to perform a quick risk assessment in devsecops

Threat Modeling Methodologies

  • Popular threat modeling frameworks in DevSecOps
  • Choosing the right threat modeling approach
  • MITRE ATT&CK and OWASP - Top 10 for threat modeling
  • Threat modeling in Agile and CI CD pipelines

Threat Identification and Prioritization

  • Identifying attack surfaces in DevSecOps
  • Risk scoring models overview
  • Using threat intelligence in threat modeling

Advanced Practices

  • Introduction to threat modeling tools
  • Continuous threat modeling
  • Risk communication
  • Data flow diagram with trust boundaries
  • STRIDE applied to DFD

Conclusion

  • Final thoughts and what to expect
40,000 Toman