Giter Club home page Giter Club logo

The Open Threat Modeling platform

IriusRisk Community Edition is a free version of IriusRisk that allows you to quickly create threat models of software and cloud architectures and then manage those threats and countermeasures throughout the rest of the SDLC, including:

  • Assigning a risk response: Accept, Mitigate or Expose
  • Apply a security standard, such as OWASP ASVS to derive the security requirements in one step
  • All threat models created in IriusRisk can be published as Templates that are visible to other users of the platform.

Getting Started

Publishing Templates

  • One of the goals of the Community edition is to start sharing a common set of threat models for typical (or not) architectures. If you've modeled a system that you believe would benefit the wider Community please publish it as a Template! This will make it visible to other users of Community who will be able to import it into their own models. The submitted templates will go through a review process and if accepted, be published here on the github site in raw XML format so that non-community users can also take advantage of it.
  • NOTE: When you publish a model, it will be removed from the Product table, you'll need to create a new product and import your template into it, to work on it again.

Try our commercial edition for these extra features

  • Manage more than 1 application. The solution has been tested with 4000+ applications.
  • Customise the rules engine, component library and threat and countermeasure knowledge-bases.
  • Create custom questionnaires and data flow rules
  • See our website for more details

IriusRisk's Projects

alloy-ui icon alloy-ui

AlloyUI is a framework built on top of YUI3 (JavaScript) that uses Bootstrap 3 (HTML/CSS) to provide a simple API for building high scalable applications

dependencycheck icon dependencycheck

OWASP dependency-check is a utility that detects publicly disclosed vulnerabilities in application dependencies.

iriusrisk-central icon iriusrisk-central

Provides content useful for IriusRisk threat modelling, including templates, API scripts, libraries and more.

iriusrisktoolkitui icon iriusrisktoolkitui

IriusRiskToolKitUI is a Python GUI client for working with several common tasks regarding security content management in IriusRisk platform.

iriustest.policy icon iriustest.policy

Example of how human-verifiable security policies can be written in IriusTest

jbehave-junit-runner icon jbehave-junit-runner

Integrate JBehave better with JUnit. Reports all Stories, Scenarios and Steps as JUnit Suites and Test Cases.

mbassador icon mbassador

A feature-rich Java event bus optimized for high-throughput in multi-threaded environments. Annotation driven, sync/async event publication, weak/strong references, dynamic event filtering

openthreatmodel icon openthreatmodel

The Open Threat Modeling Format (OTM) defines a platform independent way to define the threat model of any system.

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.