Companion-course connectionAccess Control Lists on Hosts
Host access control lists extend basic owner-group-other permissions with named user and group entries, default inheritance, and more precise authorization for shared files and directories.
Open article →Companion-course connectionCloud IAM Policy Analysis
Cloud IAM policy analysis evaluates effective permissions, conditions, inheritance, wildcard use, trust relationships, resource scope, and paths to privilege escalation.
Open article →Companion-course connectionData Dictionaries and Metadata
Data dictionaries and metadata describe fields, formats, meanings, allowed values, ownership, sensitivity, and relationships so data can be interpreted consistently.
Open article →Companion-course connectionChange Automation Evidence
Change automation evidence records what an automated change intended, who authorized it, what code and inputs ran, which targets changed, and whether outcomes matched the plan.
Open article →Companion-course connectionCloud Instance Metadata Security
Cloud instance metadata security protects workload identity and configuration services that can expose temporary credentials or sensitive context to code running on a compute resource.
Open article →Companion-course connectionCloud Key-Use Governance
Cloud key-use governance defines who and what may use encryption keys, for which operations, under what conditions, with what logging, and through which approval and recovery processes.
Open article →Companion-course connectionCloud Misconfiguration
Cloud misconfiguration is an unsafe setting in identity, networking, storage, logging, encryption, compute, data, or organizational policy that creates unintended exposure or weakens control.
Open article →Companion-course connectionExposure
Exposure is the condition of being reachable, visible, accessible, or otherwise subject to loss or attack because assets, identities, data, or services are presented to a threat.
Open article →Companion-course connectionPrivate Link and Service-Endpoint Security
Private-link and service-endpoint security governs private access to managed cloud services, including DNS, identity, routing, policy, and data-exfiltration boundaries.
Open article →Companion-course connectionServerless Event Trigger Security
Serverless event trigger security protects the queues, topics, schedules, storage events, webhooks, API routes, and other sources that invoke functions or workflows.
Open article →Companion-course connectionAccount Deprovisioning
Account deprovisioning removes or disables access, sessions, credentials, tokens, groups, roles, and recovery methods when access is no longer authorized.
Open article →Companion-course connectionAI Audit Hallucination Controls
AI audit hallucination controls prevent unsupported generated statements from being treated as evidence, criteria, citations, calculations, or conclusions.
Open article →