Security Engineering Checkpoint
Before hardening, defend the asset inventory, attacker assumptions, trust boundaries, top risks, and verification plan. Before release, demonstrate a signed artifact, SBOM, provenance verification, resolved high-severity findings, and tested incident path.