Tag: Security Design
All the articles with the tag "Security Design".
Selecting more than one tag in the sidebar shows only posts that have every selected tag.
- #Kubernetes#EKS#Hoodi
Kubernetes Namespace Design for a Hoodi Validator
A security-focused guide to designing Kubernetes namespace boundaries for a Hoodi validator architecture.
6 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS EKS SaaS (10) - Regulatory Overlays
Applying PIPA/ISMS-P and customer contractual obligations on top of the EKS SaaS baseline, and why tenant deletion is a control-plane workflow, not a single DynamoDB delete.
3 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS EKS SaaS (9) - CI/CD Verification
Gating EKS SaaS deployments on requirement IDs, from rendering Helm and Kustomize manifests to running tenant-boundary tests across Cognito pools.
3 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS EKS SaaS (8) - Evidence and Review
Why an EKS SaaS requirement is a criterion rather than proof, and how the plugin ties NetworkPolicy, IRSA, and tenant-context requirements to evidence-based status.
2 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS EKS SaaS (7) - Refresh and Lifecycle
Refreshing the EKS SaaS security contract as ingress, cluster topology, and IAM bindings change, without losing prior approvals, evidence, or requirement history.
3 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS EKS SaaS (6) - Authoring, Validation, and Publication
Writing atomic, verifiable EKS SaaS requirements for tenant identity, network isolation, IRSA, and the provisioning pipeline, validated by code before publication.
5 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS EKS SaaS (5) - Responsibility and Prioritization
Splitting EKS SaaS work across AWS, the platform team, product teams, and the SaaS operator, and why IRSA and shared controllers need more than one owner.
6 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS EKS SaaS (4) - Blast Radius
Calculating blast radius across the AWS EKS SaaS reference architecture, from a contained siloed order table to a provisioning pipeline that can reach the whole account.
5 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS EKS SaaS (3) - Threat Analysis
A ten-threat model across the AWS EKS SaaS reference architecture's shared control plane, tenant namespaces, ingress routing, and IAM Roles for Service Accounts.
8 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS EKS SaaS (2) - CIA Impact and Baseline
Calculating CIA impact for the AWS EKS SaaS reference architecture, where pooled and siloed DynamoDB models and a shared control plane both feed the result.
7 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS EKS SaaS (1) - Service Analysis
Building a confirmed service profile for AWS's EKS SaaS reference architecture, where namespace-per-tenant isolation and a shared control plane change what counts as a boundary.
6 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS ECS SaaS (10) - Regulatory Overlays
Applying PIPA/ISMS-P and customer contractual obligations on top of the ECS SaaS baseline, and why tenant deletion and cross-border data flow stay explicit review items.
5 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS ECS SaaS (9) - CI/CD Verification
Five deterministic gates that connect ECS SaaS requirements to CI/CD, from validating the requirement contract to tenant-boundary tests and image provenance.
6 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS ECS SaaS (8) - Evidence and Review
Why an ECS SaaS requirement is a criterion rather than proof, and how the plugin ties tenant-isolation, IAM, and audit requirements to evidence-based status.
5 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS ECS SaaS (7) - Refresh and Lifecycle
Refreshing the ECS SaaS security contract as isolation tiers, tenant data, and integrations change, without losing approvals, evidence, or requirement history.
5 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS ECS SaaS (6) - Authoring, Validation, and Publication
Turning the ECS SaaS work queue into atomic, verifiable requirements, validated by code and published as a versioned security contract.
6 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS ECS SaaS (5) - Responsibility and Prioritization
Turning the ECS SaaS baseline, threats, and blast-radius results into an owned, prioritized work queue, with the control plane and tenant isolation tier driving priority.
6 min read - #Security Design#Security Requirements#Plugin
Security Requirements Plugin - Kubernetes Analysis Added
Turning Kubernetes manifests into a security graph so RBAC, NetworkPolicy, service mesh, and cloud IAM relationships feed blast-radius and requirements analysis.
9 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS ECS SaaS (4) - Blast Radius
Calculating blast radius for the AWS ECS SaaS reference architecture, tracing which tenants, data, and control-plane components a threat path could reach.
5 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS ECS SaaS (3) - Threat Analysis
A STRIDE threat model across nine trust boundaries of the AWS ECS SaaS reference architecture, from tenant claim spoofing to a deployment role that can reach every tenant.
8 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS ECS SaaS (2) - CIA Impact and Baseline
Calculating confidentiality, integrity, and availability impact for the AWS ECS SaaS reference architecture, and why holding customer data pulls in a privacy baseline and a regulatory overlay.
7 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS ECS SaaS (1) - Service Analysis
Building a confirmed service profile for AWS's ECS SaaS reference architecture, before any control, threat, or blast-radius calculation.
9 min read - #Security Design#Security Requirements#Plugin
Security Requirements Plugin: New Feature - Blast Radius
How the security-requirements plugin's blast-radius stage scopes each threat across tenant, data, runtime, control, and recovery dimensions to prioritize requirements and review work.
3 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS Serverless Movie Voting App (9) - CI/CD Verification
Turning each requirement's verification metadata into a dispatchable CI/CD check, from IAM policy inspection to sentinel-based log scanning.
5 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS Serverless Movie Voting App (8) - Regulatory Overlays
Applying ISMS-P and GDPR overlays on top of the NIST baseline once the movie service adds accounts, an analytics provider, and Korean and EU users.
5 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS Serverless Movie Voting App (7) - Evidence and Review
Why a written security requirement is a criterion, not proof, and how the security-requirements plugin ties each requirement to evidence-based status.
5 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS Serverless Movie Voting App (6) - Refresh and Lifecycle
How the security-requirements plugin re-derives a security contract as a service changes, without losing prior approvals, exceptions, or audit history.
8 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS Serverless Movie Voting App (5) - Requirement Authoring and Validation
Turning a prioritized work list into stable, atomic, verifiable security requirements, then linting and merging them into a publishable contract.
8 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS Serverless Movie Voting App (4) - Responsibility and Prioritization
Assigning AWS/team/org responsibility for the selected controls and crossing them with the eight movie-service threats to produce a prioritized work list.
11 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS Serverless Movie Voting App (3) - Threat Analysis
Applying STRIDE at each trust boundary of the AWS serverless movie-rating sample, turning eight threats into eight testable security requirements.
8 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS Serverless Movie Voting App (2) - CIA Impact and Baseline
How the security-requirements plugin turns a confirmed service profile into a CIA impact rating, a NIST 800-53B baseline, and an ASVS level.
15 min read - #Security Design#Security Requirements#AWS
Security Design Review: AWS Serverless Movie Voting App (1) - Service Analysis
How the security-requirements plugin builds a confirmed service profile from an AWS serverless movie-rating sample, before any control or threat is derived.
13 min read - #Security Design#Security Requirements#Compliance
Security Requirements Plugin: First Security Activity
Claude plugin that derives security requirements from service descriptions and reviews security design.
10 min read