Security

Fully Migrated

STRIDE threat modeling, OWASP Top 10 secure coding guidelines, vulnerability scanning, and secrets lifecycle governance.

Subtopic Directory & Scope

Security Architecture Overview

Lifecycle security phases, defense-in-depth, NIST CSF core functions, and least privilege contexts

Read

Threat Modeling

STRIDE methodology, Data Flow Diagrams (DFDs), trust boundaries, and DHF risk registers

Read

Secure Coding & OWASP Top 10

Input validation, parameterized queries, and complete OWASP Top 10 mitigation code patterns

Read

Vulnerability Scanning & Testing

Plain-language SAST, SCA, DAST, IAST, pen-testing, and execution frequency schedules

Read

Secrets Management & Infrastructure

Zero hardcoded secrets, centralized key vaults, and plain-language infrastructure security

Read

Foundational Prerequisite

Explore the lifecycle phases, 24 disciplines, activities, and artifacts in Core Concepts.

View Core Concepts