Welcome to our Blog
From software security to threat modeling to compliance & risk management frameworks (and everything inbetween). We've got it covered.
Featured Posts
9 Secure by Design Tools
Achieving robust and secure applications is no easy task, see these 9 potential tools to consider for your Secure by Design strategies.
Read MoreLatest Posts
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
February 22, 2022
How to create an OTM parser
In this article we are going to create a simple Python script that parses a threat model represented as a Graphviz DOT file, and generates a threat model defined in the Open Threat Model standard.
Infrastructure as Code
February 22, 2022
Threat Modeling Software Features vs Architecture
This blog discusses two approaches to threat modeling: architectural-driven threat modeling and feature-driven threat modeling. It highlights the importance of considering security in the design stage and introduces a new library of functional components to enhance the threat modeling process, allowing developers to focus on specific user story-related threats.
Methodologies & Frameworks
Cloud Security
February 22, 2022
Introduction to the Open Threat Model standard
The Open Threat Model (OTM) standard is a versatile way to describe threat models, fostering connectivity and interoperability within the Software Development Lifecycle and cybersecurity ecosystem. It enables automation, enhances scalability, and aligns with existing design artifacts, improving threat modeling's maturity and application in various contexts.
Infrastructure as Code
Intro to Threat Modeling
February 9, 2022
Doubling Down on Threat Modeling
In 2021, threat modeling gained significant recognition and adoption, with industry accolades and government recommendations driving its importance. IriusRisk experienced substantial growth in its threat modeling platform, expanding its customer base and team, aiming to simplify and enhance threat modeling practices for secure software development in the future.
Software security
Threat Modeling
February 7, 2022
IriusRisk doubles the team and annual recurring revenue in 2021
Secure design leader doubles down on mission as threat modeling adoption grows
News
February 3, 2022
Threat Modeling: A New Strategy That Can Scale
Panel Weighs in on Overcoming Cultural Barriers to Achieve Business Benefits
Software security
Intro to Threat Modeling
Analysis
January 28, 2022
IEC/ANSI 62443 Example 3 Medical devices OT IoT Cloud Infrastructure
This comprehensive analysis delves into the architecture of a hospital gas supply control system and remote patient monitoring within the IEC/ANSI 62443 standards framework. It identifies threats, countermeasures, and weaknesses, with specific controls allocated to each component, ensuring security from cloud deployment to IoT devices.
Standards, Compliance and Regulations
Software security
December 29, 2021
Product Update: IriusRisk Version 4.0.5
We are excited to announce the release of IriusRisk 4.0.5 which includes these new enhancements and features:
Product Release
December 15, 2021
IriusRisk Unaffected by Log4j
IriusRisk is not in any way affected by CVE-2021-44228, the recent Remote Code Execution vulnerability reported in Log4j
News