Companion-course connectionAI Risk Tolerance Thresholds
AI risk tolerance thresholds translate risk appetite into measurable limits for performance, safety, privacy, bias, security, availability, cost, or human-impact indicators.
Open article →Companion-course connectionCI/CD Pipeline Security
CI/CD pipeline security protects source, build services, runners, credentials, dependencies, artifacts, approvals, and deployment paths used to deliver software.
Open article →Companion-course connectionComplete Mediation
Complete mediation requires every security-relevant access request to be checked against current authorization rules rather than relying indefinitely on an earlier decision.
Open article →Companion-course connectionTechnology Obsolescence and End-of-Life Risk
Technology obsolescence and end-of-life risk arise when unsupported hardware, software, protocols, skills, components, or suppliers can no longer meet security and operational needs.
Open article →Companion-course connectionAccess Reviews and Recertification
Access reviews verify that users, services, groups, roles, and privileged accounts still need the permissions they hold.
Open article →Companion-course connectionApplication Security Governance
Application security governance connects engineering work to risk ownership, secure design expectations, delivery controls, exceptions, evidence, and operational accountability.
Open article →Companion-course connectionArchitecture Principles and Guardrails
Architecture principles express enduring decision preferences, while guardrails define practical boundaries within which teams can design and deliver.
Open article →Companion-course connectionAudit Log Retention and Integrity
Audit log retention and integrity controls preserve security-relevant records for operational analysis, investigations, accountability, compliance, and legal needs.
Open article →Companion-course connectionAudit Logging Architecture
Audit logging architecture defines which events are produced, transported, normalized, protected, retained, correlated, analyzed, and made available for investigations and accountability.
Open article →Companion-course connectionAuthentication Factors
Authentication factors are independent categories of evidence used to prove control of an identity, commonly something known, possessed, or inherent to the user.
Open article →Companion-course connectionBackup and Recovery Strategies
Backup and recovery strategies preserve usable copies of data and system state so services can be restored after failure, error, corruption, or attack.
Open article →Companion-course connectionCryptographic Agility
Cryptographic agility is the ability to inventory, evaluate, replace, and validate cryptographic mechanisms without emergency redesign of every dependent system.
Open article →