Return this item by mail or in store within 90 days for a full refund.
Eligible for registries and wish lists
About this item
Highlights
A major update to the definitive guide on threat modeling techniques for secure by design More than just a second edition, Threat Modeling: Designing for Security in an AI World thoroughly updates and expands on Adam Shostack's classic text and structured approach to analyzing and designing systems, software, and services for security flaws to address threats and technologies that didn't exist when the first edition published.
Author(s): Adam Shostack
Computers, Security
Description
Book Synopsis
A major update to the definitive guide on threat modeling techniques for secure by design
More than just a second edition, Threat Modeling: Designing for Security in an AI World thoroughly updates and expands on Adam Shostack's classic text and structured approach to analyzing and designing systems, software, and services for security flaws to address threats and technologies that didn't exist when the first edition published. Most notably every reader will benefit from two new chapters covering using LLMs to threat model and exploring threats to LLMs, AIs, and ML Models themselves. There's a new deep focus on agile and an expansion of who's involved in threat modeling, now including non-technical product owners. All told, half of this edition is completely new or heavily revised.
Often called "the Bible of threat modeling," Shostack's approach has been adopted across industry, governments and is at the heart of OWASP's threat modeling approaches. The first edition proved to be enduring and timeless, providing techniques that continued to work as technology and development paradigms shifted.
This second edition presents an updated version of Shostack's Four-Question Framework that structures the threat modeling process from initial analysis through remediation. The specific actionable techniques proven from the first edition are updated to draw on thousands of conversations over the last decade. The guidance spans all technology. Readers gain structured methods to evaluate new additions to their technology, or business enterprise, and to select and prioritize effective defenses.
You'll also discover:
Increased discussion of cloud, IoT, and mobile
A new chapter on boundaries, including how to identify and validate them across complex system architectures
A new chapter on attack lifecycle models introduces the two most popular cyber kill chains, mapping attacker progression stages to identify optimal defensive intervention points
A new framework for selecting and implementing effective defenses, spanning and clarifying choices from designs on the back of a napkin through systems that have been in operation since before the first edition
Proven techniques for defensively managing remaining risk after threat identification, with structured and repeatable organizational approaches
A cohesive scaling chapter transitions readers from the technical skills they acquire to the business challenges of scaling threat modeling
Five legacy chapters and four appendices from the first edition are now available online at the book's website, making room in the book for all of the new content while keeping cut material available for reference
Written for engineers of all sorts, including security architects, security engineers, penetration testers, software developers building secure products, and IT administrators with security responsibilities, this Second Edition equips practitioners with structured, repeatable methods for identifying threats and designing defenses across any technology stack.
The first edition showed how secure by design was a real possibility. The second shows even more clearly how to make it happen in your technology and products.
Suggested Age: 22 Years and Up
Genre: Computers
Sub-Genre: Security
Publisher: Wiley
Theme: Network Security
Edition: 2nd Edition
Format: Paperback
Author: Adam Shostack
Language: English
Street Date: February 2, 2027
TCIN: 1013403942
UPC: 9781394413324
Item Number (DPCI): 247-62-2576
Origin: Made in the USA or Imported
If the item details aren’t accurate or complete, we want to know about it.
Shipping details
Estimated ship dimensions: 1 inches length x 1 inches width x 1 inches height
Estimated ship weight: 1 pounds
We regret that this item cannot be shipped to PO Boxes.
This item cannot be shipped to the following locations: American Samoa (see also separate entry under AS), Guam (see also separate entry under GU), Northern Mariana Islands, Puerto Rico (see also separate entry under PR), United States Minor Outlying Islands, Virgin Islands, U.S., APO/FPO, Alaska, Hawaii
Return details
This item can be returned to any Target store or Target.com.
This item must be returned within 90 days of the date it was purchased in store, delivered to the guest, delivered by a Shipt shopper, or picked up by the guest.