Learning outcomes
- Model assets, actors, threats, trust boundaries, and unacceptable consequences.
- Write testable access requirements and security invariants.
- Place a complete mediation mechanism and evaluate its failure behavior.
- Connect controls to evidence, residual risk, and recovery.
Scenario
A team must protect a production administration service. It needs to define assets, actors, threats, trust boundaries, access requirements, enforcement points, evidence, and recovery before deployment.
Ordered learning units
Security Engineering
Design complete systems that keep stated security properties under faults, misuse, and deliberate attack.
Security Understandability
Make the system, its authority, dependencies, state, failure behavior, and evidence clear enough to change and operate safely.
Security Properties
Distinguish confidentiality, integrity, availability, authenticity, accountability, and privacy in a system claim.
Asset and Protected Resource
Identify what has value, what needs protection, and which resource an access decision controls.
Actor, Subject, and Principal
Separate the real-world actor, active subject, represented principal, digital identity, and account.
Threat, Vulnerability, and Attack
Distinguish a possible harmful event, a weakness, an attempted exploit, exposure, consequence, and impact.
Trust Boundary and Data Flow
Map where data or authority crosses between components with different control, identity, or assurance assumptions.
Threat-model an identity-aware access path
Trace one protected request, find trust boundaries and bypass paths, and test which access decisions belong at the gateway and application.
Attack Tree
An attack tree decomposes one attacker goal into alternate and combined paths that can achieve it.
Turn protection needs into access requirements
Derive testable security objectives, requirements, invariants, controls, and evidence for one protected action.
Reference Monitor
Evaluate an access-control mechanism for complete mediation, tamper resistance, and evidence-based assurance.
Complete Mediation
Check every relevant access and prevent alternate paths or stale decisions from bypassing current policy.
Economy of Mechanism
Economy of mechanism keeps trusted security functions small, clear, and free of unnecessary shared behavior.
Design access controls that people can use
Use open design, clear choices, safe defaults, and observable recovery so people can operate security correctly.
Design access control during failure
Define fail-closed, fail-open, degraded, cached, and break-glass states for every access dependency before an outage.
Formal Methods and Security Models
Use precise models, invariants, and proofs to answer a bounded security question without confusing the model with the deployed system.
Model and Verify a Security Invariant
Turn one access protection need into a precise state model, analyze adverse transitions, and connect the result to deployed evidence.
Build assurance for an access control
Connect a protection need to requirements, design, implementation, tests, operations, evidence, and residual risk.
Evaluation questions
- Can you turn one unacceptable consequence into a testable requirement and invariant?
- Can you find each path to the resource and name the mechanism that mediates it?
- Can you state control evidence, failure behavior, residual risk, and recovery action?
Completion conditions
- Produce a reviewed threat model and access-system diagram for one real service.
- Demonstrate positive, negative, bypass, dependency-failure, revocation, and recovery tests.
