Privilege Elevation Stride Threat Modeling Cyber ​​Security…

$34.00

Price: $34.00
(as of May 25, 2024 15:52:55 UTC – Details)


Product description

How to play EoPHow to play EoP

Why play cybersecurity games?

Elevation of Privilege and OWASP Cornucopia are great games to help software delivery teams become more aware of threat models and actively look for specific threats. Many of the advantages of the game are cognitive or psychological and we believe that playing with physical cards plays to your strengths while taking advantage of human strengths.

3 advantages of playing games in cybersecurity:

Creativity Turning it into a game reduces risks and provides a safe environment for creative exploration of the security problem. Depth Assigning threat models to players helps utilize the detailed context known to each player. The Unexpected The random distribution of threats to players drives the sharing of tacit knowledge that cannot be reliably located in advance, such as the details of how specific components were programmed and tested.

Croupier – Elevation of Privilege Online Manual Trading Tool

How to play EoP on video callsHow to play EoP on video calls

How to play Elevation of Privilege on video calls?

The general process is as follows:

Send physical decks to each team member. Agile Stationery can help you pack and ship, or you can place bulk orders to your own address and ship later. One or more teammates collaborate to produce or update an appropriate system diagram, such as a data flow diagram. Games Master randomly generates “hands” of cards for each player using the online hand dealing tool for EoP and Cornucopia. Games Master books the meeting and sets up the video call. The calendar invite will contain each player's hands. Players work in rounds to beat each other to match the most serious threat to the system diagram, using the normal rules of the game. The game master records where the threats were found and uses the normal systems of his organization to manage the work of checking and mitigating the threat. Scores are calculated and a winner is declared.

The Elevation of Privilege card game is a game designed for developers, who are not information security professionals or experts, in the art of threat modeling.
Played as Spades, this game is a great way to build security into the development process earlier, allowing developers to find and fix vulnerabilities in systems before their designs leave the board.
The deck contains 88 cards with 78 threat cards that capture cybersecurity anti-patterns that help players attempt to find validated security flaws in a system.
The 78 threat cards are divided into six suits based on the STRIDE mnemonic: impersonation, tampering, repudiation, information disclosure, denial of service, and elevation of privilege.
The game can also be played even if not all players are in the same location using our Croupier app. The app can generate random hands for your remote workers. Players can then choose their hands from their physical decks before the game is ready to play.

Reviews

There are no reviews yet.

Be the first to review “Privilege Elevation Stride Threat Modeling Cyber ​​Security…”

Your email address will not be published. Required fields are marked *