AI Engineer - Learn how to integrate AI into software applications
40% Off Career-Building Certificates
Overview
Coursera Spring Sale
40% Off Coursera Plus Annual!
Grab it
Learn how to apply the OpenSSF threat model in enterprise environments through Ericsson's practical implementation experience in this 22-minute conference talk. Discover the systematic approach Ericsson used to validate existing security controls by mapping OpenSSF threats to ISO 27001 controls and conducting comprehensive risk assessments for each identified threat. Explore the methodology for identifying potential security gaps in open source software usage and understand how to develop corresponding mitigations based on threat modeling results. Gain actionable insights into leveraging threat modeling techniques to strengthen enterprise security frameworks around open source software, including lessons learned from real-world application of the OpenSSF End Users Working Group's comprehensive threat model designed specifically for enterprise open source environments.
Syllabus
Applying the OpenSSF Threat Model: Lessons From Ericsson - Georg Kunz & Jussi Auvinen, Ericsson
Taught by
OpenSSF