Security Excellence¶
Build secure systems by default, not as an afterthought.
Principles¶
- Least privilege — access should be the minimum required
- Shift left — security checks belong in development, not just production
- Never hardcode credentials or store secrets in repositories
Secrets Management¶
- Use a secret manager or vault solution
- Environment variables should be injected at runtime, not baked into code
- Rotate credentials regularly
- Audit access to secrets
Dependency Management¶
- Maintain an inventory of dependencies
- Run automated vulnerability scanning in CI
- Have a defined process for applying security updates
Access Control¶
- Role-based access
- Periodic access review
- Separate access levels for dev, UAT, and production
- Production data access limited to approved users only
CI/CD Security¶
- Secrets managed via pipeline secret stores, never in config files
- Dependency scanning on every build
- Static analysis for common vulnerability patterns
Strong Signals¶
- Security checks are automated in CI
- Secrets are never in source control
- Access is regularly reviewed and revoked when no longer needed
- Vulnerabilities are addressed promptly
Weak Signals¶
- Hardcoded credentials
- Shared service accounts
- No vulnerability scanning
- Production access granted by default
→ Security and compliance → Architecture Decision Records → Documentation Standards