Explicit trust boundaries
Identities, devices, sessions, content and infrastructure are modelled as separate security objects.
Identities, devices, sessions, content and infrastructure are modelled as separate security objects.
The normal workflow should be the safest available option, not a hidden exception.
Controls are also assessed by how trust can be revoked and restored.
Product language distinguishes available, evidenced, planned and independently reviewed states.
Every stage produces a reviewable working state and a clearly accountable next decision.
Assets, actors, entry paths and potential impacts are bounded.
Prevention, detection, revocation and recovery are considered together.
Tests, review, operating observation and known residual boundaries are documented.
Material changes are released with changelog, monitoring and a rollback path.