Start with the real operating path
Review how users, services, agents, data, tools, infrastructure, and administrators interact in production, including fallback, support, update, and recovery paths.
Challenge the boundaries
- Identity, authorization, delegation, tenant separation, and privileged administration.
- Sensitive-data movement, retention, external providers, and output destinations.
- Cloud and network exposure, secrets, software supply chain, logging, detection, and recovery.
- Cryptographic trust, key lifecycle, secure updates, and future migration constraints.
Make the result implementable
Translate findings into target-state choices, clear requirements, accountable owners, review checkpoints, and verification criteria that fit the engineering environment.
This guide provides general security information. It is not a certification, legal opinion, compliance determination, or guarantee of security.