• #217 - Includes No Dirt (with Bill Dougherty)

  • Jan 27 2025
  • Length: 45 mins
  • Podcast

#217 - Includes No Dirt (with Bill Dougherty)

  • Summary

  • In this episode of CISO Tradecraft, host G. Mark Hardy sits down with Bill Dougherty, CISO of Omada Health, to discuss a groundbreaking threat model called 'Includes No Dirt'. This comprehensive model integrates security, privacy, and compliance considerations, aiming to streamline and enhance threat modeling processes. The conversation covers the origin and principles of the model, its applicability across different sectors, and the essential aspects of threat modeling. Listeners are also treated to insights on handling third-party risks and adapting to emerging AI challenges. The episode provides practical advice for cybersecurity leaders looking to effectively manage and mitigate risks while reducing redundancy.

    Big Thanks to our Sponsors:

    ZeroPath - https://zeropath.com/

    CruiseCon - Use code CISOTRADECRAFT10 at https://cruisecon.com/ for 10% off registration!

    The No DIRT Threat Model can be found here: http://www.includesnodirt.com/nodirt.pdf

    Transcripts: https://docs.google.com/document/d/1vWq4Zx7pzM_B65W933m8_TE0fLKaUw3X

    Chapters

    • 03:27 The Genesis of Includes No Dirt
    • 05:05 Combining Security, Privacy, and Compliance
    • 07:24 Implementing the No Dirt Model
    • 11:42 Scoring and Evaluating Risks
    • 17:41 Third-Party Risk Management
    • 25:49 Evaluating SaaS Requests Based on Risk
    • 27:55 Adapting Threat Models for AI
    • 31:24 Principles of Minimum Necessary Data
    • 33:42 General Applicability of Security Principles
    • 35:12 Includes No Dirt: A Comprehensive Threat Model
    • 40:15 Final Thoughts and Recommendations
    Show more Show less

What listeners say about #217 - Includes No Dirt (with Bill Dougherty)

Average customer ratings

Reviews - Please select the tabs below to change the source of reviews.