Agile Stationery
OWASP® Cornucopia 2.0 Website App Edition - Threat Modeling Cards
OWASP® Cornucopia 2.0 is an updated threat modeling tool in the form of a card game designed to help software development teams identify security requirements in Agile, conventional and formal development processes.
The decks contains 80 tarot cards. Each card describes a common error or anti-pattern that allows systems to be vulnerable to attack. These vulnerabilities are chosen from data gathered by web security experts at OWASP and arranged in five key suits, with a sixth, "Cornucopia," encompassing additional elements:
- Data Validation and Encoding
- Authentication
- Session Management
- Authorization
- Cryptography
- Cornucopia
This version connects gameplay with well-researched standards like OWASP ASVS, MASVS, MASTG, SAFECode, SCP, and CAPEC, making it a versatile and comprehensive tool for security design and threat modeling without requiring prior knowledge of these standards.
Key Features:
- Updated OWASP ASVS Mapping: Now aligned with ASVS v4.0.
- Reliably Fun - consistent with Elevation of Privilege - and Hearts! Simultaneously competitive and collaborative, due to it's playful and inclusive gameplay.
- Platform and technology-agnostic - useful for everyone from PHP hackers, through Java wranglers, to PhD security experts
- Convenient tarot size - matching our collection of tarot sized threat modeling games
- Compatible with Web App projects - but also available in a mobile edition!
OWASP is a registered trademark of the OWASP Foundation.
CUSTOMISATION
Branded versions of our decks can be a great way to send a message as part of a transformation, or demonstrate leadership buy-in during any kind of cultural change.
Explore pricing for Branded Cornucopia decks here
MORE RESOURCES
- Instructions on how to play EoP
- Croupier - Play the game remotely using our online hand dealing tool