Skip to content

Create scenarios for the EoP game #3405

Description

@sydseter

Elevation of Privilege (EoP) is a serious tabletop card game designed by cybersecurity expert Adam Shostack in 2010 to make threat modeling accessible, engaging, and collaborative for software developers and architects. Instead of forcing engineering teams to sift through dry, academic security checklists, the game uses gamified mechanics to help players look at a system diagram and figure out "what can go wrong" before the code is actually built.

We are looking for contributors to help us with the help pages for each of the EoP Cards https://cornucopia.owasp.org/edition/eop

We need you to help us write a funny, but technical correct scenario with an example.
You also need to provide a STRIDE analysis of the example.
We also need you to help players answer:

  • What can go wrong?
  • What are we going to do about it?

Remember to provide authoritative references (links) under "What can go wrong" and "What are we going to do about it?" that support your claims. The point is not to create an exhaustive list of everything that can go wrong, or that should be done, but to help the player start thinking about their own situation, and if you have a hilarious and absurd example, don't be afraid to use it (E.g: 2014 Steam "Blank Password" exploit)!
It‘s better if it is a hilarious example from the real world.

As an example, see: https://cornucopia.owasp.org/cards/AA2

To contribute, simply comment here and tell me which card you will do and wait for me to confirm.

To add your text, simply click on the "View source on GitHub" button on the bottom of the page of the card you want to do. See image.

Image

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    documentationImprovements or additions to documentationhelp wantedExtra attention is needed

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions