Introduction


  • Threat assessment and benefit analysis are both activities that developers can perform with little security expertise.

Agile Security Game


  • Choosing how to use your limited resources to increase security is difficult.
  • Assess possible threats before they happen!

Threat Assessment


  • Not all “bad things” are malicious, sometimes accidents happen.
  • Threats should be considered by their likeliness and impact.

Benefit Analysis


  • Information on a threat’s likelihood, impact, and cost to address are required to make informed decisions on which threats should be addressed.