Guided Labs
Build an asset and trust-boundary model, verify password storage parameters, implement authenticated encryption through a safe library, configure a secure browser session, enforce authorization centrally, and execute key rotation and revocation.
Required evidence
Submit diagrams, versioned configuration, runnable positive and negative tests, audit events, one rejected design, remediation record, and residual-risk owner. Scanner output without mechanism-level triage does not pass.
Oral defense
Name the attacker and asset, explain the exact control property, demonstrate a denied misuse case, and execute revocation or safe recovery.
Source backbone
Use NIST SP 800-63, OWASP ASVS, relevant RFCs, and Building Secure and Reliable Systems.