RSA Conference – Threat Modeling Card Game

 

EoP_game_screen_shot

I’m here this week at RSA 2010 Conference, and I have to tell everyone that Elevation of Privilege (EoP), the threat modeling card game, has been a big hit yesterday. we printed 6,000 card decks and gave away about a 1,000 of them yesterday during the first real day of the conference. If you are here and you haven’t gotten your Elevation of Privilege Card Game, you need to come by and get a card deck for your developers and deployment team. They are going fast.  We’ve got folks getting twitter posts coming by and getting 2 and 3 decks for their security and development teams back at the office.

Elevation of Privilege (EoP) card game is the creation of Adam Shostack, and it’s a huge hit here at RSA Conference. Elevation of Privilege is the easy way to get started threat modeling. Threat modeling is a core component of the design phase in the Microsoft Security Development Lifecycle (SDL). The Elevation of Privilege (EoP) card game helps clarify the details of threat modeling and examines possible threats to software and computer systems.

To learn more about the Elevation of Privilege card game, visit our new website we launched this week at:

https://www.microsoft.com/security/sdl/eop.aspx

-George Pulikkathara, Microsoft SDL Product Management