Advanced Threat Modeling and Risk Assessment in DevSecOps
1h 38mIntermediate2025-07-11
Authors

Tino Šokić
Course details
This course provides a structured approach to understanding threat modeling principles, risk assessment methodologies, and their application within modern CI/CD pipelines. Aimed at DevSecOps professionals, developers, and security practitioners, the course explores key concepts such as attack surfaces, vulnerabilities, risk scoring models, and the use of threat intelligence to enhance security decision-making. Instructor Tino Šokić covers popular frameworks like MITRE ATT&CK and OWASP Top 10, practical techniques for performing quick risk assessments, and the tools available for managing threat modeling. Check out this course to find out how you can apply continuous threat modeling, communicate risk effectively, and integrate security seamlessly into DevSecOps workflows.
Learning objectives
Integrate threat modeling and security testing into your DevSecOps pipeline, ensuring continuous security validation throughout the software development lifecycle.
Perform systematic risk assessments by evaluating threat likelihood and impact, and develop prioritized mitigation strategies aligned with your organization’s security objectives.
Develop a risk-aware mindset for secure development and promote collaboration between development, security, and operations teams to proactively address risks.
Continuously improve threat modeling and risk management by establishing repeatable, scalable threat modeling practices.
Learning objectives
Integrate threat modeling and security testing into your DevSecOps pipeline, ensuring continuous security validation throughout the software development lifecycle.
Perform systematic risk assessments by evaluating threat likelihood and impact, and develop prioritized mitigation strategies aligned with your organization’s security objectives.
Develop a risk-aware mindset for secure development and promote collaboration between development, security, and operations teams to proactively address risks.
Continuously improve threat modeling and risk management by establishing repeatable, scalable threat modeling practices.
Skills covered
Software Development SecurityDevOps FoundationsDevOpsCybersecurityOne-Off
Concepts
0. Introduction
- 01 - Threat modeling and risk assessment in devsecops
- 02 - What you should know
1. Demystifying DevSecOps and Threat Modeling
- 03 - What is DevSecOps
- 04 - What is threat modeling
- 05 - Key concepts in threat modeling - Assets, threats, vulnerabilities, and risks
- 06 - Threat modeling in DevSecOps
- 07 - Threat modeling vs. traditional security assessments
2. Risk Assessment in DevSecOps
- 08 - Understanding risk in DevSecOps
- 09 - Threats, vulnerabilities, and impact
- 10 - Common risk assessment frameworks
- 11 - How to perform a quick risk assessment in devsecops
3. Threat Modeling Methodologies
- 12 - Popular threat modeling frameworks in DevSecOps
- 13 - Choosing the right threat modeling approach
- 14 - MITRE ATT&CK and OWASP - Top 10 for threat modeling
- 15 - Threat modeling in Agile and CI CD pipelines
4. Threat Identification and Prioritization
- 16 - Identifying attack surfaces in DevSecOps
- 17 - Risk scoring models overview
- 18 - Using threat intelligence in threat modeling
5. Advanced Practices
- 19 - Introduction to threat modeling tools
- 20 - Continuous threat modeling
- 21 - Risk communication
- 22 - Data flow diagram with trust boundaries
- 23 - STRIDE applied to DFD
6. Conclusion
- 24 - Final thoughts and what to expect