# What Security and Threat Modeling Training Should Cover

DevFeed: [What Security and Threat Modeling Training Should Cover](<https://devfeed.tech/articles/what-should-training-cover-37119.md>)

Original publisher: [Read original article](<https://shostack.org/blog/what-should-training-cover/>)

Author: Adam

Published: 2019-02-24T00:00:00Z

Content type: opinion

Language: en

Sources: [Shostack & Friends Blog](<https://devfeed.tech/sources/shostack-friends-blog.md>)

Topics: [passwords](<https://devfeed.tech/topics/passwords.md>), [Security](<https://devfeed.tech/topics/security.md>), [Learning](<https://devfeed.tech/topics/learning.md>)

Tags: [passwords](<https://devfeed.tech/tags/passwords.md>), [security](<https://devfeed.tech/tags/security.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>), [training](<https://devfeed.tech/tags/training.md>)

## AI overview

The article argues that recommendations for more training should identify specific learning goals. Using password-manager security as an example, it outlines training on attacker capabilities, spoofing and brute-force attacks, and comparing attack paths and defenses.

## Source excerpt

When suggesting that someone needs more training, consider what specific points should be covered.