Skip to main content

Module Reference

Evidence checklist: assets, actors, flows, misuse cases, protocol decision, negative tests, identity and recovery lifecycle, session contract, federation validation, authorization matrix, workload identity, secret inventory, rotation and compromise drill, residual risk.

Required evidence

Submit diagrams, versioned configuration, runnable positive and negative tests, audit events, one rejected design, remediation record, and residual-risk owner. Scanner output without mechanism-level triage does not pass.

Oral defense

Name the attacker and asset, explain the exact control property, demonstrate a denied misuse case, and execute revocation or safe recovery.

Source backbone

Use NIST SP 800-63, OWASP ASVS, relevant RFCs, and Building Secure and Reliable Systems.