Lessons
1Review an export handler from authority to output25 min read
Find authorization defects in a small code path and design regression tests.
- →Find authorization defects in a small code path and design regression tests
- →Write a regression test for authorization across alternate paths
2Scope an incident from incomplete audit evidence25 min read
Separate confirmed actions, plausible exposure and unknowns.
- →Separate confirmed actions, plausible exposure and unknowns
3Negotiate a temporary security exception25 min read
Write a bounded risk decision with compensating controls and expiry.
- →Write a bounded risk decision with compensating controls and expiry
- →Communicate residual risk with a measurable review condition
4Design a security findings collector that does not hide failure25 min read
Specify a reliable and least-privileged security automation contract.
- →Specify a reliable and least-privileged security automation contract
Skills in this course
- 01Find authorization defects in a small code path and design regression testsFind authorization defects in a small code path and design regression tests.
- 02Separate confirmed actions, plausible exposure and unknownsSeparate confirmed actions, plausible exposure and unknowns.
- 03Write a bounded risk decision with compensating controls and expiryWrite a bounded risk decision with compensating controls and expiry.
- 04Specify a reliable and least-privileged security automation contractSpecify a reliable and least-privileged security automation contract.
- 05Write a regression test for authorization across alternate pathsWrite a regression test for authorization across alternate paths.
- 06Communicate residual risk with a measurable review conditionCommunicate residual risk with a measurable review condition.