Archives
All the articles I've archived.
- #NIST SP 800-204D#CI/CD#CI/CD Security
Securing Workflows in CD Pipelines
Supply chain security measures also apply to controls during the CD process.
4 min read
- #NIST SP 800-204D#CI/CD#CI/CD Security
Securing Workflows in CI Pipelines - Secure Code Commits
Appropriate forms of testing should be performed before code commits
2 min read
- #NIST SP 800-204D#CI/CD#CI/CD Security
Securing Workflows in CI Pipelines - Integrity of Evidence Generation During Software Updates
How to ensure the integrity of evidence generation during software updates
6 min read
- #NIST SP 800-204D#CI/CD#CI/CD Security
Securing Workflows in CI Pipelines - Secure Pull-Push Operations on Repositories
Deep dive into secure Pull-Push Operations on Repositories referring to NIST SP 800-204D
6 min read
- #NIST SP 800-204D#CI/CD#CI/CD Security
Securing Workflows in CI Pipelines - Secure Build
Introduce the requirements for secure build and associated tools to secure your build stage in CI/CD pipeline.
19 min read
- #NIST#NIST SP 800-218#NIST SP 800-204D
Relationship Between NIST SP 800-218 and SP 800-204D
Review the relationship between NISTP SP 800-218 and SP 800-204D. Walk through how the SSDF specifically focuses on cloud-native application CI/CD pipelines
11 min read
- #SSDF#NIST#NIST SP 800-218
NIST SP 800-218(SSDF)
Secure Software Development Framework enhanced by Software Supply Chain Attack.
22 min read
- #Detection#SOC#Detection as Code
Palantir ADS
Palantir's methodology to enhance its detection engineering
4 min read
- #CACAO Playbook#OASIS#SOC
CACAO Playbook
Standarize and represent incident response workflow as JSON
11 min read
- #Incident Response#Vulnerability Response#Playbook
CISA Incident & Vulnerability Response Playbooks
Incident and Vulnerability Response Playbook Standard
15 min read
- #Microservices#NIST#NIST SP 800-204
NIST SP 800-204 Series
The NIST Special Publication Series for Securing Microservices.
5 min read
- #DevSecOps#DoD
DoD DevSecOps Strategy and Implementation Docs
DevSecOps documents structure of U.S Department of Defense.
5 min read
- #NIST#OSCAL#CNCF
NIST OSCAL and associated projects
An introduction to NIST OSCAL and its associated CNCF projects for compliance as code.
5 min read
- #AI#DoDD 3000.09#SOC
DoD Directive-3000.09
Why did I choose DoDD 3000.09 for UAV AI SCO.
4 min read
- #F3EAD#Red Team#AI
The F3EAD Targeting Cycle Implementation to UAV AI Red Team
Why did I implemented F3EAD,U.S military target process,to UAV AI Red team for Hackathon
2 min read
- #NIST SP 800-37(RMF)#NIST SP 800-39#NIST SP 800-30
How NIST's Risk Publications Connect
The connections and relationships between NIST Risk related publications
2 min read
- #threat-modeling#STRIDE
Threat Modeling - STRIDE
Conducting STRIDE threat modeling in detail
4 min read
- #meta
Hello, World
How this blog is built, and how posts are grouped with tags.
1 min read
