Application Security Best Practices
A starting point for application security.
Read article: Application Security Best Practices103 articles tagged Security.
A starting point for application security.
Read article: Application Security Best Practices“Defense in Depth” is the idea that no single security control is trusted to stop an attack. Instead, you stack multiple, independent layers so that if one fails, others still stand in the way.
Read article: Defense In DepthZero Trust Architecture (ZT or ZTA) is a security model / framework based on one simple idea: Never trust, always verify. From NIST, we have, the “… ZT approach is primarily focused on data and service protection but can and should be expanded to include all enterprise assets (devices,…
Read article: Zero Trust ArchitectureThe word “rule” is overused; so, I went with “precept” — a rule or principle that defines how one should think or act.
Read article: Core Security Precept: Principle of Least PrivilegeIn a previous post, we made a point of “Non-Prod Environments Must Have The Same Security Protections As Production”. In this post, we’re going to go one step further and say that your internal and external endpoints, generally, should have the same security capabilities baked into their security…
Read article: Internal Endpoints Must Have The Same Security Capabilities As External EndpointsI’ve discussed APIs and API Management in previous blog posts. These are among my older blog posts, but the points being made are, generally, still relevant. I’ve never published a blog post exclusively about API design. I have a blog post about “API Gateways and Multiple Consumer Types” where I…
Read article: API Design: Planned, Unplanned, Security and Utter ChaosI’ve been wanting to use this as a title for a blog post for a while now. It’s actually one of the quotes I have in my personal email signature. The open question has been what the topic of this blog post should be. There are so many asinine stories from fifteen years of consulting that could be…
Read article: Any Day Your Socks Don’t Burst Into Flames Is A Good DayYour non-production environments must have the same security capabilities as your production environment.
Read article: Non-Prod Environments Must Have The Same Security Protections As ProductionDigital sovereignty refers to a nation’s ability to control, regulate, and secure its digital infrastructure, data, platforms, and technological ecosystem in accordance with its own laws, values, and strategic interests.
Read article: What Is Digital Sovereignty?Some organizations keep following the same legacy, bad practices even though they know better. They keep doing it right up until the unfortunate happens.
Read article: Of Daffy Bastards And Goofy F*cks In The Land Of The Lost: Integration Anti-Patterns From The Dark Side