If you’re a Blue Teamer trying to write secure services or secure an organization that does, Threat Driven Software Development is the book you’ve been looking for. This was a deep collaboration between Michael Howard, Sherrod DeGrippo, Shawn Hernan and I - and I’m so excited to be able to get this expertise into the world.

What excites me most about this book is that there are many resources on traditional Application Security: how to protect yourself from things like Cross-Site Scripting, Prompt Injection, and many other risks so carefully described in resources like the OWASP Top 10. But there aren’t resources on how to secure and protect the operational aspects of building an online service. How should you manage keys and identities? What’s the best way to isolate production from development? How should you secure your build systems?



