Term Kind Topic What it is
Artifact Signing practice Supply Chain Security Cryptographically signing build outputs so that deployment can verify what is being run was produced by the expected pipeline from the expected source.
Break-Glass Access Emergency Access, Just-in-Time Elevation practice Identity & Access Management A pre-agreed, heavily audited path to elevated privilege for emergencies, replacing standing administrative access.
Build Provenance Artefact Attestation, SLSA Provenance practice Supply Chain Security A signed, verifiable statement of what was built, from which source, by which builder, with which dependencies - so a consumer can check that an artefact corresponds to reviewed source.
Compliance Framework SOC 2, ISO 27001, PCI DSS practice Security Architecture A published set of control requirements an organisation is assessed against, which turns security posture into evidence somebody else will check.
Consent Management practice Privacy Engineering Capturing, storing, honouring and evidencing a data subject's permissions for specific processing purposes, including withdrawal.
Continuous Compliance practice Compliance Frameworks Producing compliance evidence automatically and continuously from the systems themselves, rather than reconstructing it before an audit.
Data Discovery practice Data Classification Automatically scanning stores to find where sensitive data actually resides, as distinct from where the documentation says it should.
Data Key Caching Key Reuse Window, Envelope Key Caching practice Key Management Reusing one generated data key across a bounded number of objects, bytes and seconds, so that envelope encryption does not make one key-service request per record.
Egress Filtering practice Network Security Restricting what a workload may connect out to, which is the control that turns a compromise into a contained one.
Encryption at Rest and in Transit practice Security Architecture Protecting stored data from disclosure if the medium is obtained, and network data from disclosure if the path is observed — two different controls against two different threats.
Key Rotation practice Key Management Periodically replacing a cryptographic key with a new one while retaining the old for decrypting existing data, so exposure from any single key is bounded.
Multi-Factor Authentication MFA, 2FA practice Authentication Requiring evidence from more than one category — something you know, have, or are — so a single stolen credential is insufficient.
OWASP Top Ten practice Security Architecture A periodically updated consensus list of the most critical web application security risks, useful as a design-review checklist.
Privacy Engineering practice Privacy Engineering Building systems whose privacy properties come from their structure rather than from policy documents.
Reachability Triage Exploitability Prioritisation, Vulnerability Relevance practice Supply Chain Security Prioritising dependency vulnerabilities by whether the vulnerable code path is actually reachable and exploitable in your application, rather than by severity score - which is what makes vulnerability manageme…
Secrets Management practice Security Architecture Storing, distributing, rotating and auditing credentials so that they never live in code, images or configuration files.
Secure API Design practice Secure API Design Building an interface where the safe path is the default and the unsafe one requires deliberate effort.
Security Incident Response practice Security Incident Response Responding to a compromise — where the architecture determines whether you can detect it, contain it, and prove what happened.
STRIDE practice Threat Modelling A mnemonic for six threat categories — spoofing, tampering, repudiation, information disclosure, denial of service, elevation of privilege — walked across each component and data flow.
Supply Chain Attestation SLSA, Provenance Attestation practice Supply Chain Security A signed statement about how an artifact was produced — from which source, by which builder, with which inputs — verified before deployment.
Threat Modelling practice Security Architecture A structured exercise that identifies what can go wrong with a design, before it is built, by walking the system's trust boundaries.
Token Audience Validation Audience Restriction, aud Claim practice Tokens & JWTs Verifying that a signed token was issued for the service consuming it, without which a legitimately obtained low-privilege token is replayable against a high-privilege service.
Transactional Audit Emission Audit in the Same Transaction, Complete Audit Guarantee practice Auditability Writing the audit record in the same transaction as the state change it describes, so that a crash cannot produce a change with no record - the property that distinguishes an audit trail from application logging.