{"id":71993,"date":"2023-12-19T03:00:50","date_gmt":"2023-12-19T11:00:50","guid":{"rendered":"https:\/\/www.jamasoftware.com\/?p=71993"},"modified":"2024-01-16T10:54:46","modified_gmt":"2024-01-16T18:54:46","slug":"webinar-recap-do-326-airborne-security-assurance-threat-modeling-and-devsecops","status":"publish","type":"post","link":"https:\/\/www.jamasoftware.com\/legacy\/blog\/webinar-recap-do-326-airborne-security-assurance-threat-modeling-and-devsecops\/","title":{"rendered":"[Webinar Recap] DO-326 Airborne Security Assurance, Threat Modeling, and DevSecOps"},"content":{"rendered":"<div id=\"attachment_71994\" style=\"width: 1034px\" class=\"wp-caption aligncenter\"><img decoding=\"async\" aria-describedby=\"caption-attachment-71994\" class=\"aligncenter size-full wp-image-72282\" src=\"https:\/\/www.jamasoftware.com\/media\/2023\/12\/DO-326-Airborne-Security-Assurance-Threat-Modeling-and-DevSecOps-2.png\" alt=\"\" width=\"1024\" height=\"512\" srcset=\"https:\/\/www.jamasoftware.com\/legacy\/media\/2023\/12\/DO-326-Airborne-Security-Assurance-Threat-Modeling-and-DevSecOps-2.png 1024w, https:\/\/www.jamasoftware.com\/legacy\/media\/2023\/12\/DO-326-Airborne-Security-Assurance-Threat-Modeling-and-DevSecOps-2-300x150.png 300w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><p id=\"caption-attachment-71994\" class=\"wp-caption-text\">In this blog, we recap our webinar, &#8220;DO-326 Airborne Security Assurance, Threat Modeling, and DevSecOps&#8221; &#8211; Watch the entire thing <a href=\"\/webinar\/do-326-airborne-security-assurance-threat-modeling-and-devsecops\" target=\"_blank\" rel=\"noopener\">HERE<\/a>.<\/p><\/div>\n<hr \/>\n<h3>Cyber vulnerabilities can have a significant impact on safety-critical systems.<\/h3>\n<p>Today there is an unprecedented level of digital interconnectivity in everything from vehicle sensors to rovers on the surface of Mars. The aerospace industry has a high degree of cyber connectedness where a negative impact could cause harm to not only aircraft but financial systems, company reputations, international relations, or even physical harm to humans and property.<\/p>\n<p>During this informative session, <a href=\"https:\/\/www.linkedin.com\/in\/carybryczek\/\" target=\"_blank\" rel=\"noopener\">Cary Bryczek<\/a>, Director of Aerospace &amp; Defense Solutions at Jama Software<sup>\u00ae<\/sup>, discusses how Jama Software applies a cybersecure-by-design approach to meeting DO-326A\/DO-356A for aircraft systems and how this can be extended to the defense domain.<\/p>\n<p>In this webinar, we covered:<\/p>\n<ul>\n<li>Applying the Airworthiness Security Assurance Process<\/li>\n<li>Threat (attack) modeling methods<\/li>\n<li>Tracing security measures to requirements and tests<\/li>\n<li>The role of requirements in DevSecOps tool ecosystems<\/li>\n<\/ul>\n<p><script src=\"https:\/\/fast.wistia.com\/embed\/medias\/z3gwzfgkdh.jsonp\" async><\/script><script src=\"https:\/\/fast.wistia.com\/assets\/external\/E-v1.js\" async><\/script><\/p>\n<div class=\"wistia_responsive_padding\" style=\"padding: 56.25% 0 0 0; position: relative;\">\n<div class=\"wistia_responsive_wrapper\" style=\"height: 100%; left: 0; position: absolute; top: 0; width: 100%;\">\n<div class=\"wistia_embed wistia_async_z3gwzfgkdh seo=false videoFoam=true\" style=\"height: 100%; position: relative; width: 100%;\">\n<div class=\"wistia_swatch\" style=\"height: 100%; left: 0; opacity: 0; overflow: hidden; position: absolute; top: 0; transition: opacity 200ms; width: 100%;\"><img decoding=\"async\" style=\"filter: blur(5px); height: 100%; object-fit: contain; width: 100%;\" src=\"https:\/\/fast.wistia.com\/embed\/medias\/z3gwzfgkdh\/swatch\" alt=\"\" aria-hidden=\"true\" \/><\/div>\n<\/div>\n<\/div>\n<\/div>\n<h2>DO-326 Airborne Security Assurance, Threat Modeling, and DevSecOps<\/h2>\n<p><b>Cary Bryczek:<\/b> What we&#8217;re seeing today is just an unprecedented level of digital interconnectivity in seemingly every system out there. The aviation industry has a high degree of cyber connectedness where a negative impact could really cause harm to not just humans and property, but company reputations, international relations, or financial systems.<\/p>\n<p>What we&#8217;re going to see today is how Jama Connect can provide a cyber secure-by-design approach to meeting the many aspects of <a href=\"https:\/\/www.sae.org\/learn\/content\/c1949\/\" target=\"_blank\" rel=\"noopener\">DO-326<\/a> and <a href=\"https:\/\/standards.globalspec.com\/std\/10398650\/RTCA%20DO-356\" target=\"_blank\" rel=\"noopener\">DO-356<\/a>, or <a href=\"https:\/\/www.eurocae.net\/training\/aircraft-cyber-security-development-and-continuing-airworthiness\/\" target=\"_blank\" rel=\"noopener\">ED-202 and ED-203<\/a> in Europe, the Middle East, and Africa (EMEA.) What we&#8217;re going to see is we&#8217;re going to apply the airworthiness security process that&#8217;s inside of DO-326, and use Jama Connect&#8217;s <a href=\"https:\/\/www.jamasoftware.com\/solutions\/requirements-traceability\" target=\"_blank\" rel=\"noopener\">Live Traceability\u2122<\/a> to trace security measures to security requirements, trace security requirements to testing, look and see how a threat analysis can all be incorporated into a single platform.<\/p>\n<p>What is <a href=\"https:\/\/www.cisa.gov\/sites\/default\/files\/2023-04\/principles_approaches_for_security-by-design-default_508_0.pdf\" target=\"_blank\" rel=\"noopener\">Cybersecurity by Design<\/a>? So one of the things that we see a lot is in the tool ecosystem is a very disconnected set of processes and tools. So whether you&#8217;re tracing and using tools that do requirements identification, tracing those to verifications and hardware and software designs, or whether you&#8217;re using tools to do aircraft security analysis and tracing those to security architectures and security V&amp;V, we&#8217;re noticing the disconnectedness of the processes in the tool ecosystem is causing product delays, cost overruns, product failures, audit failures, late identification of defects, and lack of visibility because the ecosystem is very disconnected, is taking place. There&#8217;s poor requirement coordination. Change management is hard between software and hardware, and you have a high degree of manual effort required to produce the traceability that&#8217;s required for certification. And you&#8217;re seeing this after the fact and Excel is used everywhere. Desktop tools are prevalent in the engineering of these systems, and it&#8217;s difficult to integrate desktop tools and Excel files into and across the ecosystem for product development.<\/p>\n<hr \/>\n<h4><span style=\"color: #ff6600;\"><strong>RELATED: <\/strong><span style=\"color: #0000ff;\"><a style=\"color: #0000ff;\" href=\"\/wistia-jama-connect-features-in-five\/jama-connect-features-in-five-space-systems-framework\" target=\"_blank\" rel=\"\u201cnoopener noopener\">Jama Connect<sup>\u00ae<\/sup> Features in Five: Space Systems Framework<\/a><\/span><\/span><\/h4>\n<hr \/>\n<p><b>Bryczek:<\/b> So what is Live Traceability? Live Traceability in Jama Connect gives the ability for any engineer at any time to see the most up-to-date upstream and downstream information for any requirement, no matter the stage of the systems development or however many siloed tools it spans. Now, this Live Traceability is important because it&#8217;s required by the industry standards like we&#8217;ve seen in aviation development and Live Traceability delivers a huge productivity improvement and it reduces the risk and the delay that happens when you have a disconnected tool environment.<\/p>\n<p>So we&#8217;re going to talk about DO-326. DO-326 is really a set of standards jointly developed by <a href=\"https:\/\/www.rtca.org\/news\/advancing-aviation-standards-rtca-and-eurocae-renew-commitment-through-updated-memorandum-of-cooperation\/\" target=\"_blank\" rel=\"noopener\">RTCA and EUROCAE<\/a>. It came about in 2006. It includes a few separate standards. DO-326 and ED-202 really is about the airworthiness security process specification. It explains the fundamental concepts behind airworthiness cybersecurity. DO-356 and ED-203, the airworthiness security methods and considerations, this explains how to perform cybersecurity investments, how to evaluate threats, and security measures of the system. How do you apply the mitigation measures? DO-355, we&#8217;re not going to really talk about that one today, but it&#8217;s applicable to if there are changes in an already certified system. So one of the most relevant documents you&#8217;re going to start with even before you start down the path for cybersecurity, is creating your product information and security risk assessment document. You&#8217;re going to perform an analysis of this, and this analysis should be conducted according to the standards.<\/p>\n<p>So what exactly is airworthiness? So airworthiness security is the protection of the airworthiness of the aircraft from intentional unauthorized electronic interaction. So existing safety processes don&#8217;t consider intentional disruption. They look at the faults and failures of an aircraft or the aircraft system on a whole. But DO-326 is specifically looking at intentional human-initiated actions with the potential to affect the aircraft due to some unauthorized access or disclosure or causing some denial or disruption of the information systems, the networks, and the software that&#8217;s running on these aircraft systems. So this also might include things like malware or infected devices or the logical effects of any external systems. So the purpose of the airworthiness security process within DO-326 is to establish that when subjected to this unauthorized interaction, the aircraft is going to remain in a condition for safe operation.<\/p>\n<p>So like I said earlier, DO-326 describes the what and DO-356 is the how. I&#8217;m sure that you guys have carefully looked at both of these guidelines and these are images from the guidelines. But I just wanted to point out what we&#8217;re going to talk about today. We&#8217;re going to talk about how the airworthiness security process and threats are mapped in Jama and how you can have security assurance and the risk assessment process from DO-356, how those can be conducted in Jama Connect itself. As you know, DO-326 live in its own. You&#8217;re having supporting processes from the development of the aircraft, the development of the system, <a href=\"\/whitepaper\/do-178c-best-practices-for-engineers-and-managers?kw=&amp;cpn=18314264399&amp;utm_source=google&amp;utm_medium=cpc&amp;utm_campaign=nam-search-dsa-nonb_max-value&amp;utm_adgroup=All%20Pages&amp;utm_term=&amp;utm_content=600524153670&amp;_bm=18314264399140721801549&amp;gad_source=1&amp;gclid=Cj0KCQiAj_CrBhD-ARIsAIiMxT_M1rjUt50JvcE-lyG-GQ9YAmeaywHvNRc0L1kdraxxuV8Lot_rvG8aAgp0EALw_wcB\" target=\"_blank\" rel=\"noopener\">DO-178<\/a>, <a href=\"\/whitepaper\/arp4761a-intro-for-engineers-and-managers-whitepaper?kw=&amp;cpn=18314264399&amp;utm_source=google&amp;utm_medium=cpc&amp;utm_campaign=nam-search-dsa-nonb_max-value&amp;utm_adgroup=All%20Pages&amp;utm_term=&amp;utm_content=600524153670&amp;_bm=18314264399140721801549&amp;gad_source=1&amp;gclid=Cj0KCQiAj_CrBhD-ARIsAIiMxT-b-c6Em9uF-x-c4nUkQI0mOHDDlEPJ97kLnJpl6OmfFadVGirzQ58aAs6sEALw_wcB\" target=\"_blank\" rel=\"noopener\">ARP-4754<\/a> are all interacting and being conducted at the same time. So there&#8217;s no linear, do this first, do this next, do this later. All of these processes are taking place pretty much simultaneously or iteratively as you design and develop the aircraft system.<\/p>\n<p>So the airworthiness security process from a basic level, it&#8217;s again, it&#8217;s the protection of the aircraft from intentional unauthorized electronic interaction. There are four steps for the basic process. We&#8217;re going to first identify the system assets and its parameters. The second step is to identify the threats for all of those assets, identify those risks for each of the threats, so what might happen, and then create controls and mitigations for those risks. You&#8217;re going to be adjudicating the degree of harm and assigning a security assurance level, the strongest being SAL3 or the least would be a SAL zero where there&#8217;s this limited or protection needs required. So there&#8217;s a way to grade those as well.<\/p>\n<hr \/>\n<h4><span style=\"color: #ff6600;\"><strong>RELATED: <\/strong><span style=\"color: #0000ff;\"><a style=\"color: #0000ff;\" href=\"\/blog\/traceable-agile-speed-and-quality-are-possible-for-software-factories-in-safety-critical-industries\" target=\"_blank\" rel=\"\u201cnoopener noopener\">Traceable Agile \u2013 Speed AND Quality Are Possible for Software Factories in Safety-critical Industries<\/a><\/span><\/span><\/h4>\n<hr \/>\n<p><b>Bryczek:<\/b> The inside of Jama Connect itself, this image describes essentially the architecture of what you&#8217;re going to see that what we have in the product. We have a template that you can use to facilitate this. It sits alongside of our template that&#8217;s used for ARP-4754, and DO-178, or <a href=\"\/whitepaper\/do-254-benefits-versus-costs-for-engineers-and-managers?kw=&amp;cpn=18314264399&amp;utm_source=google&amp;utm_medium=cpc&amp;utm_campaign=nam-search-dsa-nonb_max-value&amp;utm_adgroup=All%20Pages&amp;utm_term=&amp;utm_content=601136946224&amp;_bm=18314264399140721801549&amp;gad_source=1&amp;gclid=Cj0KCQiAj_CrBhD-ARIsAIiMxT9OmAlF382omwXmkYUDaxOb_zPEpYXUZ9XiL5SVti3mTQuBrCXElSAaAl8AEALw_wcB\" target=\"_blank\" rel=\"noopener\">DO-254<\/a>. The orange assets essentially is the data model that we&#8217;re using to capture the different types of things in the system. So we have assets, we have vulnerabilities. Those are tied to different threat assessments or a threat assessment is performed on these types of objects. We have security measures, we have the security architecture elements, and those feed into the security requirements. This comes pre-configured out of the box. We also have an area where you going to capture the data for that kind of thing.<\/p>\n<p>Having this sort of a data model enables engineers to really perform the analysis to understand, all right, which assets have I not assessed yet? What&#8217;s the workflow? Who has reviewed the threat assessment? Have the security measures been satisfied by security requirements? Have we done security testing of the system? So this sort of data model enables the traceability to be instantiated and allows engineers to really more easily create the kind of a content. So one of the benefits you see of using Jama is that the security process is not disconnected from the design and development of the aircraft system itself. It&#8217;s done alongside. So that way you have that earlier touch points between the functional aircraft, design engineers and the security engineers. So you&#8217;re building in that secure by design approach.<\/p>\n<hr \/>\n<h4 style=\"text-align: center;\"><span style=\"color: #ff6600;\"><strong>Deep dive into the seven steps of DO-326A compliance in this related whitepaper: <\/strong><span style=\"color: #0000ff;\"><br \/>\n<a style=\"color: #0000ff;\" href=\"\/whitepaper\/cybersecurity-in-the-air-addressing-modern-threats-with-do-326a\" target=\"_blank\" rel=\"\u201cnoopener noopener\">Cybersecurity in the Air: Addressing Modern Threats with DO-326A<\/a><\/span><\/span><\/h4>\n<hr \/>\n<input class=\"fooboxshare_post_id\" type=\"hidden\" value=\"71993\"\/>","protected":false},"excerpt":{"rendered":"<p>Cyber vulnerabilities can have a significant impact on safety-critical systems. Today there is an unprecedented level of digital interconnectivity in everything from vehicle sensors to rovers on the surface of Mars. The aerospace industry has a high degree of cyber connectedness where a negative impact could cause harm to not only aircraft but financial systems, [&hellip;]<\/p>\n","protected":false},"author":74,"featured_media":72282,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[854],"tags":[841,843,840],"industry":[582],"class_list":["post-71993","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-compliance-regulation","tag-jama-connect-platform","tag-product-development-management","industry-aerospace-defense"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.1 (Yoast SEO v28.1) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>DO-326 Airborne Security Assurance - Jama Software<\/title>\n<meta name=\"description\" content=\"In this blog, we recap our recent webinar discussing DO-326A\/DO-356A for aircraft systems and how it can be extended to the defense domain.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.jamasoftware.com\/blog\/webinar-recap-do-326-airborne-security-assurance-threat-modeling-and-devsecops\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"[Webinar Recap] DO-326 Airborne Security Assurance, Threat Modeling, and DevSecOps\" \/>\n<meta property=\"og:description\" content=\"In this blog, we recap our recent webinar discussing DO-326A\/DO-356A for aircraft systems and how it can be extended to the defense domain.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.jamasoftware.com\/blog\/webinar-recap-do-326-airborne-security-assurance-threat-modeling-and-devsecops\/\" \/>\n<meta property=\"og:site_name\" content=\"Jama Software\" \/>\n<meta property=\"article:published_time\" content=\"2023-12-19T11:00:50+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2024-01-16T18:54:46+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.jamasoftware.com\/legacy\/media\/2023\/12\/DO-326-Airborne-Security-Assurance-Threat-Modeling-and-DevSecOps-2.png\" \/>\n\t<meta property=\"og:image:width\" content=\"1024\" \/>\n\t<meta property=\"og:image:height\" content=\"512\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Cary Bryczek\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Cary Bryczek\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.jamasoftware.com\\\/blog\\\/webinar-recap-do-326-airborne-security-assurance-threat-modeling-and-devsecops\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.jamasoftware.com\\\/blog\\\/webinar-recap-do-326-airborne-security-assurance-threat-modeling-and-devsecops\\\/\"},\"author\":{\"name\":\"Cary Bryczek\",\"@id\":\"https:\\\/\\\/www.jamasoftware.com\\\/#\\\/schema\\\/person\\\/9b39a0731f372096043a8047490a6a2d\"},\"headline\":\"[Webinar Recap] DO-326 Airborne Security Assurance, Threat Modeling, and DevSecOps\",\"datePublished\":\"2023-12-19T11:00:50+00:00\",\"dateModified\":\"2024-01-16T18:54:46+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.jamasoftware.com\\\/blog\\\/webinar-recap-do-326-airborne-security-assurance-threat-modeling-and-devsecops\\\/\"},\"wordCount\":1524,\"image\":{\"@id\":\"https:\\\/\\\/www.jamasoftware.com\\\/blog\\\/webinar-recap-do-326-airborne-security-assurance-threat-modeling-and-devsecops\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.jamasoftware.com\\\/media\\\/2023\\\/12\\\/DO-326-Airborne-Security-Assurance-Threat-Modeling-and-DevSecOps-2.png\",\"keywords\":[\"Compliance &amp; Regulation\",\"Jama Connect Platform\",\"Product Development &amp; Management\"],\"articleSection\":[\"Cybersecurity\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.jamasoftware.com\\\/blog\\\/webinar-recap-do-326-airborne-security-assurance-threat-modeling-and-devsecops\\\/\",\"url\":\"https:\\\/\\\/www.jamasoftware.com\\\/blog\\\/webinar-recap-do-326-airborne-security-assurance-threat-modeling-and-devsecops\\\/\",\"name\":\"DO-326 Airborne Security Assurance - Jama Software\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.jamasoftware.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.jamasoftware.com\\\/blog\\\/webinar-recap-do-326-airborne-security-assurance-threat-modeling-and-devsecops\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.jamasoftware.com\\\/blog\\\/webinar-recap-do-326-airborne-security-assurance-threat-modeling-and-devsecops\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.jamasoftware.com\\\/media\\\/2023\\\/12\\\/DO-326-Airborne-Security-Assurance-Threat-Modeling-and-DevSecOps-2.png\",\"datePublished\":\"2023-12-19T11:00:50+00:00\",\"dateModified\":\"2024-01-16T18:54:46+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.jamasoftware.com\\\/#\\\/schema\\\/person\\\/9b39a0731f372096043a8047490a6a2d\"},\"description\":\"In this blog, we recap our recent webinar discussing DO-326A\\\/DO-356A for aircraft systems and how it can be extended to the defense domain.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.jamasoftware.com\\\/blog\\\/webinar-recap-do-326-airborne-security-assurance-threat-modeling-and-devsecops\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.jamasoftware.com\\\/blog\\\/webinar-recap-do-326-airborne-security-assurance-threat-modeling-and-devsecops\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.jamasoftware.com\\\/blog\\\/webinar-recap-do-326-airborne-security-assurance-threat-modeling-and-devsecops\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.jamasoftware.com\\\/media\\\/2023\\\/12\\\/DO-326-Airborne-Security-Assurance-Threat-Modeling-and-DevSecOps-2.png\",\"contentUrl\":\"https:\\\/\\\/www.jamasoftware.com\\\/media\\\/2023\\\/12\\\/DO-326-Airborne-Security-Assurance-Threat-Modeling-and-DevSecOps-2.png\",\"width\":1024,\"height\":512},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.jamasoftware.com\\\/blog\\\/webinar-recap-do-326-airborne-security-assurance-threat-modeling-and-devsecops\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.jamasoftware.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"[Webinar Recap] DO-326 Airborne Security Assurance, Threat Modeling, and DevSecOps\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.jamasoftware.com\\\/#website\",\"url\":\"https:\\\/\\\/www.jamasoftware.com\\\/\",\"name\":\"Jama Software\",\"description\":\"Jama Connect\u00ae #1 in Requirements Management\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.jamasoftware.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.jamasoftware.com\\\/#\\\/schema\\\/person\\\/9b39a0731f372096043a8047490a6a2d\",\"name\":\"Cary Bryczek\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a037e48a1a760fe3b6d2e1c05f38735d28ef1bbce8d9df186550c69d2aad7d7c?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a037e48a1a760fe3b6d2e1c05f38735d28ef1bbce8d9df186550c69d2aad7d7c?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a037e48a1a760fe3b6d2e1c05f38735d28ef1bbce8d9df186550c69d2aad7d7c?s=96&d=mm&r=g\",\"caption\":\"Cary Bryczek\"},\"description\":\"Cary is the Director of Solutions Architecture for Aerospace and Defense with a focus on the specialized business and technical needs unique to this market. She helps lead the company in Systems Engineering and Model Based Systems Engineering (MBSE) domain. She has over 25 years of experience leading Systems Engineering in the A&amp;D industry with roles at the US Government, Lockheed Martin, PTC, and Jama Software. She is a member of the International Counsel on Systems Engineering and member of the Women in Aerospace organization. Outside of work she enjoys playing jazz guitar and gardening around her farm which sometimes requires the operation of tractors and UAVs.\",\"sameAs\":[\"https:\\\/\\\/www.linkedin.com\\\/in\\\/carybryczek\\\/\"],\"url\":\"https:\\\/\\\/www.jamasoftware.com\\\/blog\\\/author\\\/cbryczek\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"DO-326 Airborne Security Assurance - Jama Software","description":"In this blog, we recap our recent webinar discussing DO-326A\/DO-356A for aircraft systems and how it can be extended to the defense domain.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.jamasoftware.com\/blog\/webinar-recap-do-326-airborne-security-assurance-threat-modeling-and-devsecops\/","og_locale":"en_US","og_type":"article","og_title":"[Webinar Recap] DO-326 Airborne Security Assurance, Threat Modeling, and DevSecOps","og_description":"In this blog, we recap our recent webinar discussing DO-326A\/DO-356A for aircraft systems and how it can be extended to the defense domain.","og_url":"https:\/\/www.jamasoftware.com\/blog\/webinar-recap-do-326-airborne-security-assurance-threat-modeling-and-devsecops\/","og_site_name":"Jama Software","article_published_time":"2023-12-19T11:00:50+00:00","article_modified_time":"2024-01-16T18:54:46+00:00","og_image":[{"width":1024,"height":512,"url":"https:\/\/www.jamasoftware.com\/legacy\/media\/2023\/12\/DO-326-Airborne-Security-Assurance-Threat-Modeling-and-DevSecOps-2.png","type":"image\/png"}],"author":"Cary Bryczek","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Cary Bryczek","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.jamasoftware.com\/blog\/webinar-recap-do-326-airborne-security-assurance-threat-modeling-and-devsecops\/#article","isPartOf":{"@id":"https:\/\/www.jamasoftware.com\/blog\/webinar-recap-do-326-airborne-security-assurance-threat-modeling-and-devsecops\/"},"author":{"name":"Cary Bryczek","@id":"https:\/\/www.jamasoftware.com\/#\/schema\/person\/9b39a0731f372096043a8047490a6a2d"},"headline":"[Webinar Recap] DO-326 Airborne Security Assurance, Threat Modeling, and DevSecOps","datePublished":"2023-12-19T11:00:50+00:00","dateModified":"2024-01-16T18:54:46+00:00","mainEntityOfPage":{"@id":"https:\/\/www.jamasoftware.com\/blog\/webinar-recap-do-326-airborne-security-assurance-threat-modeling-and-devsecops\/"},"wordCount":1524,"image":{"@id":"https:\/\/www.jamasoftware.com\/blog\/webinar-recap-do-326-airborne-security-assurance-threat-modeling-and-devsecops\/#primaryimage"},"thumbnailUrl":"https:\/\/www.jamasoftware.com\/media\/2023\/12\/DO-326-Airborne-Security-Assurance-Threat-Modeling-and-DevSecOps-2.png","keywords":["Compliance &amp; Regulation","Jama Connect Platform","Product Development &amp; Management"],"articleSection":["Cybersecurity"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.jamasoftware.com\/blog\/webinar-recap-do-326-airborne-security-assurance-threat-modeling-and-devsecops\/","url":"https:\/\/www.jamasoftware.com\/blog\/webinar-recap-do-326-airborne-security-assurance-threat-modeling-and-devsecops\/","name":"DO-326 Airborne Security Assurance - Jama Software","isPartOf":{"@id":"https:\/\/www.jamasoftware.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.jamasoftware.com\/blog\/webinar-recap-do-326-airborne-security-assurance-threat-modeling-and-devsecops\/#primaryimage"},"image":{"@id":"https:\/\/www.jamasoftware.com\/blog\/webinar-recap-do-326-airborne-security-assurance-threat-modeling-and-devsecops\/#primaryimage"},"thumbnailUrl":"https:\/\/www.jamasoftware.com\/media\/2023\/12\/DO-326-Airborne-Security-Assurance-Threat-Modeling-and-DevSecOps-2.png","datePublished":"2023-12-19T11:00:50+00:00","dateModified":"2024-01-16T18:54:46+00:00","author":{"@id":"https:\/\/www.jamasoftware.com\/#\/schema\/person\/9b39a0731f372096043a8047490a6a2d"},"description":"In this blog, we recap our recent webinar discussing DO-326A\/DO-356A for aircraft systems and how it can be extended to the defense domain.","breadcrumb":{"@id":"https:\/\/www.jamasoftware.com\/blog\/webinar-recap-do-326-airborne-security-assurance-threat-modeling-and-devsecops\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.jamasoftware.com\/blog\/webinar-recap-do-326-airborne-security-assurance-threat-modeling-and-devsecops\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.jamasoftware.com\/blog\/webinar-recap-do-326-airborne-security-assurance-threat-modeling-and-devsecops\/#primaryimage","url":"https:\/\/www.jamasoftware.com\/media\/2023\/12\/DO-326-Airborne-Security-Assurance-Threat-Modeling-and-DevSecOps-2.png","contentUrl":"https:\/\/www.jamasoftware.com\/media\/2023\/12\/DO-326-Airborne-Security-Assurance-Threat-Modeling-and-DevSecOps-2.png","width":1024,"height":512},{"@type":"BreadcrumbList","@id":"https:\/\/www.jamasoftware.com\/blog\/webinar-recap-do-326-airborne-security-assurance-threat-modeling-and-devsecops\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.jamasoftware.com\/"},{"@type":"ListItem","position":2,"name":"[Webinar Recap] DO-326 Airborne Security Assurance, Threat Modeling, and DevSecOps"}]},{"@type":"WebSite","@id":"https:\/\/www.jamasoftware.com\/#website","url":"https:\/\/www.jamasoftware.com\/","name":"Jama Software","description":"Jama Connect\u00ae #1 in Requirements Management","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.jamasoftware.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.jamasoftware.com\/#\/schema\/person\/9b39a0731f372096043a8047490a6a2d","name":"Cary Bryczek","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a037e48a1a760fe3b6d2e1c05f38735d28ef1bbce8d9df186550c69d2aad7d7c?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a037e48a1a760fe3b6d2e1c05f38735d28ef1bbce8d9df186550c69d2aad7d7c?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a037e48a1a760fe3b6d2e1c05f38735d28ef1bbce8d9df186550c69d2aad7d7c?s=96&d=mm&r=g","caption":"Cary Bryczek"},"description":"Cary is the Director of Solutions Architecture for Aerospace and Defense with a focus on the specialized business and technical needs unique to this market. She helps lead the company in Systems Engineering and Model Based Systems Engineering (MBSE) domain. She has over 25 years of experience leading Systems Engineering in the A&amp;D industry with roles at the US Government, Lockheed Martin, PTC, and Jama Software. She is a member of the International Counsel on Systems Engineering and member of the Women in Aerospace organization. Outside of work she enjoys playing jazz guitar and gardening around her farm which sometimes requires the operation of tractors and UAVs.","sameAs":["https:\/\/www.linkedin.com\/in\/carybryczek\/"],"url":"https:\/\/www.jamasoftware.com\/blog\/author\/cbryczek\/"}]}},"_links":{"self":[{"href":"https:\/\/www.jamasoftware.com\/legacy\/wp-json\/wp\/v2\/posts\/71993","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.jamasoftware.com\/legacy\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.jamasoftware.com\/legacy\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.jamasoftware.com\/legacy\/wp-json\/wp\/v2\/users\/74"}],"replies":[{"embeddable":true,"href":"https:\/\/www.jamasoftware.com\/legacy\/wp-json\/wp\/v2\/comments?post=71993"}],"version-history":[{"count":0,"href":"https:\/\/www.jamasoftware.com\/legacy\/wp-json\/wp\/v2\/posts\/71993\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.jamasoftware.com\/legacy\/wp-json\/wp\/v2\/media\/72282"}],"wp:attachment":[{"href":"https:\/\/www.jamasoftware.com\/legacy\/wp-json\/wp\/v2\/media?parent=71993"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.jamasoftware.com\/legacy\/wp-json\/wp\/v2\/categories?post=71993"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.jamasoftware.com\/legacy\/wp-json\/wp\/v2\/tags?post=71993"},{"taxonomy":"industry","embeddable":true,"href":"https:\/\/www.jamasoftware.com\/legacy\/wp-json\/wp\/v2\/industry?post=71993"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}