Finding where trust changes in a system, what crosses each boundary, and what an attacker would try there.
Topics
- Trust Boundaries
- Browser to server, service to service, user to admin and agent to tool: every point where the level of trust changes.
- Threat Modeling
- Asking what can go wrong, with methods such as STRIDE and attack trees, early enough to change the design.
- Attack Surface
- Counting every input, endpoint, dependency and credential an attacker could reach, and shrinking that list.
- Least Privilege
- Giving each person, service and agent only the access its job requires.
- Defense in Depth and Secure Defaults
- Layered controls that fail closed, so a single mistake does not become a breach.