Companion-course connectionSecurity Control Placement
Security control placement determines where a preventive, detective, responsive, or recovery mechanism must sit in the architecture to see, decide, and act on the intended behavior.
Open article →Companion-course connectionBGP Route Security
BGP route security applies policy, filtering, validation, monitoring, and operational discipline to reduce accidental or malicious route announcements.
Open article →Companion-course connectionCloud Hybrid Connectivity
Hybrid connectivity joins cloud environments with data centers, offices, edge locations, or other providers through VPNs, dedicated links, and routing services.
Open article →Companion-course connectionCloud Network Flow Logs
Cloud network flow logs record summarized connection metadata from virtual networks, interfaces, gateways, and security controls for monitoring, troubleshooting, and investigation.
Open article →Companion-course connectionCloud Subnets, Routes, and Gateways
Cloud subnets divide address space, route tables determine forwarding, and gateways connect workloads to other networks or provider services.
Open article →Companion-course connectionConditional Access for Hybrid Networks
Conditional access for hybrid networks combines identity, device, location, risk, application, and session context to make dynamic access decisions across cloud and on-premises resources.
Open article →Companion-course connectionControl Baselines and Tailoring
A control baseline is a starting set of safeguards selected for a defined impact or risk context; tailoring adjusts that set to the system, organization, threats, and applicable requirements.
Open article →Companion-course connectionHybrid Network Architecture
Hybrid network architecture connects on-premises, cloud, edge, remote, and third-party environments through explicitly designed zones, routes, identities, controls, and failure domains.
Open article →Companion-course connectionNetwork Architecture Validation
Network architecture validation proves that a design and its implementation satisfy documented business, technical, security, compliance, availability, and operational requirements.
Open article →Companion-course connectionPrivacy Rights Request Verification
Privacy rights request verification confirms that a requester is entitled to act without collecting excessive new data or exposing another person’s information.
Open article →Companion-course connectionRelative Estimation and Sizing
Relative estimation compares the effort, complexity, uncertainty, and risk of work items using shared reference points instead of pretending to know precise duration too early.
Open article →Companion-course connectionAttack Paths
An attack path is a sequence of reachable systems, identities, trust relationships, weaknesses, and actions that could let an adversary move from an initial foothold to a valuable objective.
Open article →