🥳  No mês de Aniversário da Caroli.org, você estuda com 30% off usando o cupom: 7ANOSCAROLI. Escolha o seu treinamento!


Precisa de ajuda para escolher o seu
treinamento ou tem alguma dúvida?

APA Threat modeling

Threat modeling is a process by which potential threats can be identified, enumerated, and mitigations can be prioritized. Depending on your inception context, you might have to explicitly add an activity for raising the conversation and listing the threat scenarios to be considered. The APA threat modeling activity organize the threats by exploring the Attackers, the Principals and the Assets.

Step by step:

      1. Explain the following template to everyone: Attackers use Principals to get Assets

    – Attacker –the threat agent, the individual or organisation who performs the malicious activities to an asset.
    – Principal – the entity that can be authenticated
    – Asset – the valuable data and/or equipment to be secure

    1. Ask the participants to list the Attackers, the Principals and the Assets
    2. Describe the threats by combining Attackers, Principals and Assets into the template
    3. Have a conversation about the threats (consider categorising and rating each threat)

    step 2 example (obfuscated for confidentiality)

    Example: Hactivist uses Website to get Bank account info

    I learned this activity from Rodrigo Rech, a security specialist.


>> This content is part of a series on inception activities.


Paulo Caroli

Paulo Caroli is the author of the best-selling book “Lean Inception: How to Align People and Build the Right Product” (the first on a series of books on business agility). He's also the creator of FunRetrospectives.com , a site and book about retrospectives, futurospectives and team building activities. Caroli writes on this blog frequently. Receive the next post in your email. Sign up here.
Build the MVP Canvas

Build the MVP Canvas

In the ‘Build the MVP Canvas’ activity, you’ll explore a dynamic tool inspired by lean startup principles—the Minimum Viable Product (MVP) Canvas. This visual chart empowers you to validate and refine product ideas systematically. It guides you through defining the MVP’s proposal, personas, journeys, features, metrics, and schedule. Step by step, you’ll understand each block, fill it with relevant information, and ensure alignment. Whether concluding a Lean Inception workshop or standalone, the MVP Canvas bridges ideas to action, turning concepts into customer-centric products.

read more
Participation Level Activity: Clarify the Participation Level and Engage Your Workshop Participants Effectively

Participation Level Activity: Clarify the Participation Level and Engage Your Workshop Participants Effectively

The “Participation Level” activity is a simple yet effective tool for collecting participant information and gauging their involvement in a workshop or session. By utilizing color-coded post-it notes and encouraging interactive introductions, this activity not only enhances understanding but also infuses energy and engagement into the group. Whether you’re organizing an inception or any collaborative session, this activity sets a vibrant tone and fosters a sense of active participation among attendees.

read more

Pin It on Pinterest