Security foundations and governance are the operating model underneath every technical control. The goal is to make secure cloud usage easier than insecure cloud usage, then verify the controls with useful signals.

Foundation Themes

  • Account vending and landing zone controls
  • Control ownership and exception workflows
  • Policy-as-code and secure-by-default modules
  • Security service delegation and organizational guardrails
  • Evidence collection for audits and operational reviews
  • Metrics that show coverage, drift, and remediation quality

Domain Map

Questions Worth Writing About

  • What control prevents the most damage if credentials leak?
  • Which findings need an alert, and which need an automated ticket?
  • Where should security live: platform modules, policy engines, CI, runtime detection, or all of the above?
  • How do we keep least privilege from becoming a spreadsheet theater project?

0 items under this folder.