Design Security for Real Human Systems
Build security that survives deception, pressure, support, recovery, insider authority, poor incentives, and daily work.
Topic index
Learn the threats, controls, and operating practices that reduce access risk.
Topic index
Pomerium records authorization decisions for protected routes. Operators can send logs to an owned analysis and retention path and can add selected MCP fields. The surrounding applications, endpoints, identity provider, and network still need their own event sources.
2 learning paths
Build security that survives deception, pressure, support, recovery, insider authority, poor incentives, and daily work.
Govern, observe, detect, investigate, preserve evidence, contain, recover, and assure an identity-aware access system.
33 related guides
Map cost, benefit, authority, information, liability, and feedback so a control works after teams and vendors optimize their own goals.
Connect assets, threats, likelihood, impact, controls, evidence, assumptions, and residual risk for one access system.
Trace one agent action through identity, delegation, policy, approval, credential, tool, target, result, and future revocation.
Turn role-specific risks into practiced tasks, usable tools, behavior measures, feedback, and control improvements.
Join authentication, authorization, proxy, and application evidence without confusing one event for another.
Connect a protection need to requirements, design, implementation, tests, operations, evidence, and residual risk.
Design and validate signals for route bypass, credential abuse, stale authority, policy drift, and control failure.
Put an access system into service and remove it with verified ownership, authority, dependencies, evidence, and final state.
Disable identity, revoke credentials and sessions, isolate routes, and measure the last accepted harmful action.
Define fail-closed, fail-open, degraded, cached, and break-glass states for every access dependency before an outage.
Use open design, clear choices, safe defaults, and observable recovery so people can operate security correctly.
Keep access controls safe through dependency failures, limit damage, recover service, and prove the restored state.
Collect enough access evidence for detection and investigation while limiting identity detail, linkability, sensitive content, recipients, and retention.
Assign owners and review, approve, deploy, observe, expire, and retire access policy with evidence and rollback.
Build, deploy, verify, update, and recover a role-specific minimal service without broad host or control-plane authority.
Prioritize exposure and authority, deploy verified patches, watch behavior, and retain a safe rollback path.
Receive, reproduce, triage, remediate, verify, disclose, deploy, and learn from application vulnerability reports.
Review, test, deploy, attest, observe, and reconcile access configuration without allowing hidden runtime drift.
Convert evaluated threat information into owned prevention, detection, hunting, patching, response, and risk decisions.
Inventory protocol profiles, detect use, migrate consumers, and remove obsolete versions without permanent compatibility paths.
Grant short-lived and emergency authority with explicit scope, expiry, approval, monitoring, revocation, and review.
Move access policy from protection need through review, testing, staged deployment, observation, rollback, and retirement.
Generate, store, issue, distribute, rotate, revoke, destroy, and recover credentials and cryptographic keys.
Separate token expiry, introspection, revocation, session termination, and replay response and measure the effective denial time.
Collect and preserve access evidence with documented integrity, context, custody, privacy, and reproducibility.
Verify source, dependencies, builds, provenance, artifacts, deployment, and runtime identity for access components.
Control collection, use, sharing, storage, logging, backup, recovery, retention, deletion, and sanitization for one data class.
Restore known-good identity, policy, trust, routes, evidence, and service after compromise or control failure.
Separate stored secrets from projected, rotated credentials and reduce exposure through identity-bound delivery and use.
Prepare, investigate, contain, recover, and learn when identity or access authority is abused or compromised.
Prove that access systems can meet recovery objectives without restoring compromised authority, code, policy, or data.
Distinguish and test guessing, stuffing, spraying, phishing, MFA fatigue, recovery abuse, and session theft.
Turn an access alert into a supported finding, a bounded response decision, and useful feedback for the detection.
62 related terms
Inventory protected resources, identities, routes, policies, credentials, dependencies, owners, and recovery paths.
State who can attack the system, what they want, what they can do, where they start, and what constrains them.
Inventory agent identities, hosts, models, tools, servers, credentials, owners, versions, targets, and provenance.
Agent blast radius is the maximum credible effect that an agent can cause through its tools, credentials, data access, network reach, and chained actions.
Stop one false result, repeated action, or unavailable dependency from propagating through agents and tools with growing impact.
Keep agent credentials isolated by user, task, audience, and tool and control storage, use, rotation, and revocation.
Verify the origin, version, integrity, permissions, and change process for agent code, models, prompts, tools, and metadata.
An attack surface is the set of boundary points where an attacker can try to enter a system, cause an effect, or extract data.
An attack tree decomposes one attacker goal into alternate and combined paths that can achieve it.
Record enough structured evidence to explain and test an access decision without storing credentials or excess personal data.
Authorization drift is the gap that develops when effective access no longer matches intended access.
Create isolated, complete, recoverable copies and prove they restore current service without old compromise, authority, or expired data.
Issue, deploy, rotate, revoke, recover, and retire certificates and private keys without breaking name or trust validation.
A Cloud Access Security Broker is a policy enforcement point that mediates use of cloud services.
Turn evaluated information about adversaries, behavior, infrastructure, vulnerabilities, and incidents into a time-bounded security decision.
A data breach is the loss of control, compromise, unauthorized disclosure, acquisition, or access to sensitive information.
Place complementary controls across distinct failure domains so one failure does not expose the protected asset.
Model how traffic, expensive valid work, state, queues, dependencies, identity, and recovery controls can make a service unavailable.
Evaluate whether a detection observes the intended behavior with useful fidelity, timeliness, coverage, context, response, and manageable error.
Identify, collect, preserve, examine, analyze, and report digital evidence with stated scope, methods, time, integrity, and uncertainty.
Control policy, identity, revocation, key, context, and quota state across replicas with explicit freshness and failure semantics.
Encryption transforms plaintext into ciphertext under a cryptographic key. Symmetric encryption uses a shared secret key.
Endpoint security is the set of controls used to manage and protect devices that access organizational data and services.
Show that evidence is authentic enough for its purpose and record every collection, transfer, access, transformation, analysis, and disposition.
A hidden trust boundary exists when one component accepts another component's identity, authority, data, or result without an explicit enforced rule.
Identity-aware rate limiting bounds request volume by accountable subject, client, resource, action, and cost.
Distinguish short-lived technical observables from adversary tactics, techniques, and procedures used to build more durable detection and response.
Reduce harmful action by people or partners who hold legitimate access, knowledge, proximity, or influence, whether intentional or accidental.
An intrusion detection system monitors events and produces alerts when it finds signs of an incident or policy violation.
Create, change, and remove identity and access state when a person or workload enters, changes, or leaves a role.
Lateral movement is the post-compromise use of techniques to enter and control additional remote systems or accounts in an environment.
Understand malicious code that steals, persists, disrupts, spies, moves, or changes systems and prepare to contain and rebuild affected trust.
A man-in-the-middle attack places an adversary between two parties to intercept, relay, or change communication without their knowledge.
Model Context Protocol security is the set of controls that protects hosts, clients, servers, tools, authorization flows, and downstream resources.
MITRE ATT&CK catalogs observed adversary tactics and techniques that can guide hypotheses, detections, and investigations.
OWASP is the Open Worldwide Application Security Project.
Limit authority by resource, action, context, and time, then remove access when the assigned function ends.
Learn how direct and indirect prompt injection can drive unsafe agent actions, and how least privilege and authorization reduce impact.
Ransomware is malware used to deny access to data or systems and demand payment. Many operators also steal data and threaten disclosure.
Set and test the maximum target time to restore a service and maximum acceptable data loss after disruption.
Measure how long a disabled identity, authenticator, session, claim, or permission can continue to authorize action.
Secure enclave is a general phrase for an isolated execution area, but it is also used in product names such as Apple's Secure Enclave.
Remove a system, route, identity, key, dependency, and data without leaving reachable shadow service or breaking another security control.
An SWG applies policy to user access to internet web services.
Qualify, categorize, prioritize, enrich, assign, and escalate a potential incident from evidence, asset criticality, identity, scope, and impact.
Security protects stated assets and properties, while compliance evaluates obligations against defined criteria and evidence.
Distinguish a control claim, verification, validation, assurance argument, and the evidence that supports each conclusion.
Build role-specific learning around real tasks, safe alternatives, practice, feedback, and measured behavior instead of annual completion.
Security culture makes ownership, review, reporting, response, and recovery normal parts of access-system work.
Security information and event management collects, normalizes, stores, searches, and correlates security-relevant event and log data from multiple sources.
A security postmortem turns an incident timeline, contributing conditions, and response evidence into owned system changes.
Connect a credible threat, likelihood, consequence, uncertainty, and stakeholder impact to an explicit risk decision.
Security telemetry uses logs, metrics, traces, and events to answer defined detection, investigation, and control questions.
Make the system, its authority, dependencies, state, failure behavior, and evidence clear enough to change and operate safely.
Record useful access evidence while preventing credentials, excess personal data, tampering, and indefinite retention.
Shared responsibility assigns each access control, dependency, decision, evidence source, and recovery action to an owner.
Distinguish component inventory, build provenance, attestations, signatures, and the policy that verifies them.
Reduce a deployed system to required services, identities, interfaces, privileges, configurations, and recovery paths, then keep it there.
Proactively test a bounded threat hypothesis in existing evidence when no alert has yet confirmed the activity.
Distinguish a possible harmful event, a weakness, an attempted exploit, exposure, consequence, and impact.
Tool surface area is the full set of operations, inputs, external resources, and privilege effects that tools make available to an agent.
A TEE is an execution environment isolated from software outside the TEE. It protects selected code and data against a defined set of threats.