• Home
  • About
  • Blog
  • Contact

← All posts

Application Security Best Practices

April 12, 2026by Robert Broeckelmann
  • Application Security
  • Security

A starting point for application security.

  • Defense In Depth
  • Zero Trust Architecture
  • Core Security Precept: Principle of Least Privilege
  • A Vendor DMZ Pattern
  • Internal Endpoints Must Have The Same Security Capabilities As External Endpoints
  • Non-Prod Environments Must Have The Same Security Protections As Production
  • Achieving Application Environment Isolation
  • No, You Shouldn’t Use Production Data For Testing
  • Of Daffy Bastards And Goofy F*cks In The Land Of The Lost: Integration Anti-Patterns From The Dark Side
  • SOFTWARE SUPPLY CHAIN SECURITY: CI/CD/CT PIPELINES AND SECURITY TOOLS — PART 1
  • SOFTWARE SUPPLY CHAIN SECURITY: CI/CD/CT PIPELINES AND SECURITY TOOLS — PART 2
  • Network Segmentation: Macro, Micro, and the Building Blocks
  • Input Validation: Because Users Are Creative, and Attackers Are More Creative
  • Secure Code Reviews: Finding Security Issues Before Attackers Do

Some of the craziest things I’ve seen done in the name of security were supposedly in pursuit of best practices. Context matters; so does commonsense.

Originally published on Medium.

More articles

Bearer, Proof of Possession, and Sender Vouches: Three Ways to Trust an Identity

August 20, 2026
  • Access Tokens
  • Authorization
  • Identity & Access Management

One of the most fundamental questions in any identity or authorization system is how does the system know that the party presenting a credential is actually entitled to use it?

Read article →: Bearer, Proof of Possession, and Sender Vouches: Three Ways to Trust an Identity

Holder of Key vs. Proof of Possession: Two Sides of Cryptographic Identity

August 19, 2026
  • Access Tokens
  • Authentication
  • Identity & Access Management

For years, identity protocols have used phrases such as Holder of Key, Proof of Possession, Key Binding, and Bearer almost interchangeably.

Read article →: Holder of Key vs. Proof of Possession: Two Sides of Cryptographic Identity

Content Security Policy: Putting the Browser on a Security Diet

August 19, 2026
  • Application Security
  • Web Application Security
  • Security

Web applications have become remarkably powerful.

Read article →: Content Security Policy: Putting the Browser on a Security Diet
Site design by Yvette Richter Design
Contact Us|Privacy Policy

Proud sponsor of the Open Source IDPTools Project. Github project

© 2026 IYA Cyber Security. All rights reserved.

This site uses cookies for analytics and to remember this choice. See the Privacy Policy for what is collected and how to opt out.