
OWASP Cumulus: Threat Modeling the Ops of DevOps (god2025)
Chaos Computer Club - recent events feed · Christoph Niehoff
November 26, 202526m 8s
Audio is streamed directly from the publisher (cdn.media.ccc.de) as published in their RSS feed. Play Podcasts does not host this file. Rights-holders can request removal through the copyright & takedown page.
Show Notes
In this presentation, we will highlight how threat modeling, as a proactive measure, can increase security in DevOps projects.
We will introduce OWASP Cumulus, a threat modeling card game designed for threat modeling the Ops part of DevOps processes. This game (in combination with similar games like Elevation of Privilege or OWASP Cornucopia) enables DevOps teams to take the security responsibility for their project in a lightweight and engaging way.
Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/
about this event: https://c3voc.de
Topics
564822025god2025Track 2god2025-enggod2025Day 1