Powered by Blogger.
🌏World roaming Software Technology Evangelist. Proud Indian, Bought up from Coimbatore, Tamilnadu, INDIA. Pointing towards share of Knowledge. 😎
  • Programming ▼
    • DotNet
      • C# Coding Standards
    • Cloud
    • Microsoft 365/ SharePoint
    • SQL
    • Angular / ReactJS / NodeJS
    • Salesforce
    • Magento
    • Python
    • Mobile App Development
    • Database
    • DevOps
    • Automation Testing
    • User Experience
  • Learning ▼
    • Roadmap
    • Trainings
    • E-Books
    • Quick References
    • Certifications
    • Self Improvement
    • Productivity
    • TED Talks
    • Kids Programming
  • SW Engineering ▼
    • Agile
    • Software Design
    • Architecture Samples
    • Best Practises
    • Technologies and Tools
    • Open Sources
    • Free Softwares
  • Leadership ▼
    • Program Management
    • Product Management
    • Project Management
    • People Management
  • Job Search ▼
    • Interview Tips
    • Career Handbook
    • Resume Templates
    • Sample Profiles
    • Cover Letter Samples
    • HR Interview Questions
    • Job Websites List
    • Coding Site Links
    • TedEx Talks
    • International Jobs
  • Emerging ▼
    • Innovation
    • Machine Learning
    • Artificial Intelligence
    • Generative AI
    • AI Tools
    • Big Data
    • Data Science
    • Data Analytics & Visualization
    • Cyber Security
    • Microsoft Azure
    • Amazon Web Services
    • Cryptography
    • ChatBots
    • Internet of Things (IoT)
    • Mixed Reality /AR/VR
  • Misc. ▼
    • Travel
    • Photography
    • Health Tips
    • Medical Tips
    • Home Designs
    • Gardening
  • Samples ▼
    • GitHub
    • Executive Dashboard
    • Chatbot
    • Image Generator
    • Jay's Link Tree
  • Favourites▼
    • Saran Kitchen Hut
    • World of Akshu
    • Saran & Akshu - Other Links


If you need to master Secure application design, Threat Modelling adopting best practices are mandatory.

Threat Modelling is a proactive security practice for identifying potential threats, understanding attack paths, assessing risk, and defining mitigations before vulnerabilities become incidents.

 

A simple flow is:

Identify Assets → Map Architecture → Identify Threats → Assess Risk → Mitigate → Validate & Monitor

It is commonly integrated into the SDLC and DevSecOps to support Security by Design and shift security activities earlier in delivery.

🌐 Areas Used

  • Application Security — Web, mobile, SaaS, APIs, microservices
  • Cloud & Infrastructure — Azure, AWS, hybrid cloud, containers, Kubernetes
  • Data & Privacy — PII, sensitive data, encryption, data flows
  • Identity & Access — Authentication, authorization, privileged access
  • APIs & Integrations — REST/GraphQL, third-party services, event-driven systems
  • AI & GenAI — LLMs, RAG, AI agents, prompts, vector databases, data leakage
  • Business Processes — Critical workflows, financial transactions, supply chains
  • DevSecOps — CI/CD, SAST, DAST, dependency and security testing

🧰 Tools

Tool

Primary Use

Microsoft Threat Modeling Tool

Architecture & threat analysis

OWASP Threat Dragon

Open-source threat modelling

IriusRisk

Enterprise threat modelling

ThreatModeler

Automated enterprise modelling

Microsoft Defender for Cloud

Cloud security posture

Snyk / Checkmarx

Code & application security

Burp Suite

Web application testing

Lucidchart / draw.io

Architecture & data-flow diagrams

🔬 Methodologies

  • STRIDE — Spoofing, Tampering, Repudiation, Information Disclosure, Denial of Service, Elevation of Privilege
  • PASTA — Risk-centric methodology focused on business impact and attack simulation
  • DREAD — Damage, Reproducibility, Exploitability, Affected Users, Discoverability
  • LINDDUN — Privacy-focused threat modelling
  • Attack Trees — Visualizes paths an attacker may take toward an objective
  • VAST — Visual, Agile and Simple Threat modelling for scalable environments

📈 Benefits

  • Reduces security risks and attack surface
  • Identifies design weaknesses early
  • Enables Security by Design
  • Reduces remediation cost and late-stage rework
  • Improves architecture and engineering decisions
  • Strengthens compliance and risk management
  • Improves collaboration between Security, Architecture, Engineering and Product teams
  • Supports resilient cloud, SaaS and AI/GenAI solutions
  • Builds customer and stakeholder confidence

✅ Best Practices

  1. Start early — Begin during requirements and architecture, not just before release.
  2. Identify critical assets — Focus on sensitive data, identities, systems and business processes.
  3. Map data flows — Document components, trust boundaries, APIs, external dependencies and data stores.
  4. Use a consistent methodology — Apply STRIDE or another framework appropriate to the system.
  5. Prioritize risk — Focus mitigation on threats with significant business or security impact.
  6. Collaborate cross-functionally — Include architects, developers, security, operations and product stakeholders.
  7. Integrate with DevSecOps — Connect threat modelling with SAST, DAST, penetration testing and CI/CD.
  8. Cover modern architectures — Include cloud, APIs, containers, third-party services and AI/GenAI.
  9. Validate mitigations — Verify that identified controls actually address the threat.
  10. Keep models updated — Revisit the model when architecture, technology, integrations or business requirements change.

 

Bottom line: Threat modelling helps organizations anticipate threats, prioritize risk, and engineer security into systems from the beginning rather than treating security as a final-stage testing activity.

 

♻️ Save and Repost this to help your network.

➕ Follow for more interesting Tech contents:

🔗 https://planetjai.blogspot.com 

 

Tags:

#ThreatModelling #SecureSDLC-Practices #BestPractices #JayavelcsArticles

Hi All, 

Excited to take part at AI Hackathon on July 2026 targeted for Guinness World Record Attempt on Largest AI Training by Kanz based out of Saudia Arabia. 
 
It was a 5 days workshop covering various tools - Riplit AI, Mini Studio, Suno, Claude, N8N, ElevenLabs, Heygen.
 
Post the training workshop, Everyone were building Apps using AI and submitted along with Solution.  
 
Below is the link of my App submission. 
 
https://try.ka.nz/ai/jayavelchakravarthysrinivasan  
 
Overall, The workshop was interesting from Kanz team. 
 
 

 App Screenshots:

 
 






 

Tags:

#AIHackathon, #Kanz 


 


Shift-Left is a proactive software delivery and operations strategy that moves quality, security, testing, compliance, and risk management activities earlier ("to the left") in the Software Development Lifecycle (SDLC). The goal is to identify and resolve issues as early as possible rather than discovering them during deployment or production.

 

🎯 Operational Areas Where Shift-Left Is Used

  • Requirements & Planning – Early validation of business requirements and acceptance criteria.
  • Architecture & Design – Security, scalability, and performance reviews during design.
  • Development – Code reviews, static code analysis, secure coding practices.
  • Testing – Automated unit, integration, API, and regression testing.
  • Security (DevSecOps) – SAST, dependency scanning, threat modeling, vulnerability assessments.
  • Infrastructure & Cloud Operations – Infrastructure as Code (IaC) validation and policy compliance checks.
  • Compliance & Governance – Early regulatory, privacy, and audit control validation.
  • Performance Engineering – Load, stress, and performance testing integrated into CI/CD pipelines.

 

🎯 Key Benefits

✔ Early Defect Detection – Reduces costly fixes later in the lifecycle.
✔ Improved Software Quality – Higher reliability and fewer production issues.
✔ Faster Delivery – Accelerates releases through automation and continuous validation.
✔ Enhanced Security – Vulnerabilities identified before deployment.
✔ Lower Operational Costs – Prevents expensive production outages and rework.
✔ Better Compliance – Regulatory and governance requirements addressed earlier.
✔ Increased Team Collaboration – Developers, QA, Security, and Operations work together from the start.
✔ Higher Customer Satisfaction – Improved product stability, performance, and user experience.

 

🎯 Example

In a traditional approach, a security vulnerability might be discovered during production testing. With Shift-Left DevSecOps, automated security scans run during code commits, allowing developers to remediate vulnerabilities immediately, reducing risk and deployment delays.

In summary: Shift-Left promotes "building quality, security, and compliance into the process from the beginning rather than inspecting them at the end."

 

 

♻️ Save and Repost this to help your network.

➕ Follow for more interesting Tech contents:

🔗 https://planetjai.blogspot.com 

 

Tags: 

#Shift-LeftApproach #DeliveryPractices #BestPractices #JayavelcsArticles

 

Newer Posts
Older Posts

Total Posts

Search this Site

Connect with Me

Translate Articles

Total Pageviews


Contributors

My photo
Jayavel Chakravarthy Srinivasan
Professional:I'm a Software Techie, Specialized in Microsoft technologies. Worked in CMM Level 5 organizations like EPAM, KPMG, Bosch, Honeywell, ValueLabs, Capgemini and HCL. I have done freelancing. My interests are Software Development, Graphics design and Photography.
Certifications:I hold PMP, SAFe 6, CSPO, CSM, Six Sigma Green Belt, Microsoft and CCNA Certifications.
Academic:All my schooling life was spent in Coimbatore and I have good friends for life. I completed my post graduate in computers(MCA). Plus a lot of self learning, inspirations and perspiration are the ingredients of the person what i am now.
Personal Life:I am a simple person and proud son of Coimbatore. I studied and grew up there. My mom and wife are proud home-makers and greatest cook on earth. My kiddo in her junior school.
Finally:I am a film buff and like to travel a lot. I visited 3 countries - United States of America, Norway and United Kingdom. I believe in honesty after learning a lot of lessons the hard way around. I love to read books & articles, Definitely not journals. :)
View my complete profile

My Achievements

My Achievements

My Favorite Links

  • Saran & Akshu Links
  • Saran Kitchen Hut
  • World of Akshu
  • Ashok Raja Blog

Subscribe To

Posts
Atom
Posts
All Comments
Atom
All Comments

Contact Form

Name

Email *

Message *

Blog Archive

  • ▼  2026 (37)
    • ▼  October (1)
      • Reliable Response Design Tips for User’s question ...
    • ►  September (2)
    • ►  July (1)
    • ►  June (6)
    • ►  May (7)
    • ►  April (7)
    • ►  March (7)
    • ►  February (5)
    • ►  January (1)
  • ►  2025 (65)
    • ►  December (4)
    • ►  November (3)
    • ►  October (3)
    • ►  August (1)
    • ►  July (6)
    • ►  June (7)
    • ►  May (26)
    • ►  April (1)
    • ►  March (3)
    • ►  February (1)
    • ►  January (10)
  • ►  2024 (134)
    • ►  December (3)
    • ►  November (8)
    • ►  October (11)
    • ►  September (2)
    • ►  August (1)
    • ►  July (39)
    • ►  June (8)
    • ►  May (4)
    • ►  April (9)
    • ►  March (6)
    • ►  February (33)
    • ►  January (10)
  • ►  2023 (16)
    • ►  December (12)
    • ►  August (2)
    • ►  March (1)
    • ►  January (1)
  • ►  2022 (14)
    • ►  December (1)
    • ►  August (6)
    • ►  July (3)
    • ►  June (2)
    • ►  February (1)
    • ►  January (1)
  • ►  2021 (16)
    • ►  December (1)
    • ►  November (2)
    • ►  October (2)
    • ►  August (1)
    • ►  July (2)
    • ►  June (2)
    • ►  May (2)
    • ►  March (2)
    • ►  February (1)
    • ►  January (1)
  • ►  2020 (36)
    • ►  December (1)
    • ►  November (15)
    • ►  October (2)
    • ►  September (1)
    • ►  July (1)
    • ►  June (2)
    • ►  May (4)
    • ►  March (2)
    • ►  February (6)
    • ►  January (2)
  • ►  2019 (14)
    • ►  December (3)
    • ►  November (1)
    • ►  September (2)
    • ►  August (1)
    • ►  June (1)
    • ►  May (3)
    • ►  March (2)
    • ►  January (1)
  • ►  2018 (61)
    • ►  November (3)
    • ►  October (4)
    • ►  September (4)
    • ►  August (5)
    • ►  July (4)
    • ►  June (4)
    • ►  May (7)
    • ►  April (7)
    • ►  March (5)
    • ►  February (1)
    • ►  January (17)
  • ►  2017 (55)
    • ►  December (1)
    • ►  November (7)
    • ►  October (7)
    • ►  September (8)
    • ►  July (4)
    • ►  June (7)
    • ►  May (4)
    • ►  April (4)
    • ►  March (1)
    • ►  February (2)
    • ►  January (10)
  • ►  2016 (45)
    • ►  December (1)
    • ►  November (5)
    • ►  October (2)
    • ►  September (7)
    • ►  August (3)
    • ►  July (3)
    • ►  June (1)
    • ►  May (3)
    • ►  April (5)
    • ►  March (3)
    • ►  February (3)
    • ►  January (9)
  • ►  2015 (88)
    • ►  December (5)
    • ►  November (2)
    • ►  October (6)
    • ►  September (6)
    • ►  August (3)
    • ►  July (6)
    • ►  June (7)
    • ►  May (12)
    • ►  April (6)
    • ►  March (11)
    • ►  February (10)
    • ►  January (14)
  • ►  2014 (159)
    • ►  December (16)
    • ►  November (13)
    • ►  October (42)
    • ►  September (12)
    • ►  August (19)
    • ►  July (3)
    • ►  June (17)
    • ►  May (10)
    • ►  April (12)
    • ►  March (7)
    • ►  February (4)
    • ►  January (4)
  • ►  2013 (192)
    • ►  December (7)
    • ►  November (2)
    • ►  October (3)
    • ►  September (10)
    • ►  August (25)
    • ►  July (17)
    • ►  June (22)
    • ►  May (22)
    • ►  April (24)
    • ►  March (17)
    • ►  February (22)
    • ►  January (21)
  • ►  2012 (204)
    • ►  December (21)
    • ►  November (35)
    • ►  October (47)
    • ►  September (27)
    • ►  August (6)
    • ►  July (21)
    • ►  June (16)
    • ►  May (7)
    • ►  April (9)
    • ►  March (4)
    • ►  February (3)
    • ►  January (8)
  • ►  2011 (70)
    • ►  December (8)
    • ►  November (5)
    • ►  October (3)
    • ►  September (2)
    • ►  August (7)
    • ►  July (3)
    • ►  June (30)
    • ►  May (3)
    • ►  April (3)
    • ►  March (1)
    • ►  February (3)
    • ►  January (2)
  • ►  2010 (30)
    • ►  December (1)
    • ►  September (4)
    • ►  August (1)
    • ►  July (1)
    • ►  June (1)
    • ►  May (4)
    • ►  April (6)
    • ►  March (5)
    • ►  February (2)
    • ►  January (5)
  • ►  2009 (40)
    • ►  December (4)
    • ►  November (6)
    • ►  October (4)
    • ►  September (5)
    • ►  August (4)
    • ►  July (3)
    • ►  June (4)
    • ►  May (8)
    • ►  March (1)
    • ►  February (1)
  • ►  2008 (6)
    • ►  December (1)
    • ►  September (1)
    • ►  May (1)
    • ►  April (2)
    • ►  February (1)
  • ►  2007 (7)
    • ►  December (1)
    • ►  November (2)
    • ►  October (1)
    • ►  July (1)
    • ►  May (2)

Recent Posts

Followers

Report Abuse

FOLLOW ME @INSTAGRAM

Popular Posts

  • Stay Wow - Health Tips from Sapna Vyas Patel
    Referred URL https://www.facebook.com/sapnavyaspatel WATCH WEIGHT LOSS VIDEO: http://www.youtube.com/ watch?v=S_dlkjwVItA ...
  • Calorie Count chart For food and drinks
    Referred URL http://deepthidigvijay.blogspot.co.uk/p/health-diet-calorie-charts.html http://www.nidokidos.org/threads/37834-Food-Calorie-...
  • SharePoint 2010 Interview Questions and Answers
    Referred URL http://www.enjoysharepoint.com/Articles/Details/sharepoint-2010-interview-questions-and-answers-148.aspx 1.What is SharePoint...
  • 150 Best Windows Applications Of Year 2010
    Referred URL : http://www.addictivetips.com/windows-tips/150-best-windows-applications-of-year-2010-editors-pick/?utm_source=feedburner...
  • Web Developer Checklist by Mads Kristensen
    Referred Link -  http://webdevchecklist.com/ Web Developer Checklist Get the extension  Chrome  |  Firefox  |  Edge Menu Bes...
  • WCF and REST Interview Questions
    What is WPF? The Windows Presentation Foundation (WPF) is a next generation graphics platform that is part of...
  • Remove double tap to unlock feature on samsung galaxy core2
    Double tap to unlock is a feature of Talkback, so if your will disable Talkback, double tap to unlock will also be disabled. To disable doub...
  • Difference Between Content Editor and Script Editor webpart
    Referred Link -  http://jeffas.com/content-editor-vs-script-editor-webpart/ Content editor web part is a place holder for creating rich ...
  • SPFolder related operations in SharePoint
      1) Get SPListItem(s) of a particular SPFolder SPList splist; SPFolder spfolder; //Get the required folder instance SPQuery spquery = new ...

Comments

Created with by BeautyTemplates | Distributed by blogger templates