Skip to content

Practical handbook

Cybersecurity Engineering Handbook

A practical security engineering field manual for secure design, implementation, review, operations, defense, and recovery.

A layered security citadel surrounded by trust boundaries, detection paths, controls, and recovery systems.

Reading order

Contents

Part 1

Part I - Orientation and Minimum Security Bar

3 entries
  1. 01 How to Use This Handbook
  2. 02 Security Principles Engineers Can Apply
  3. 03 The Minimum Security Bar

Part 2

Part II - Govern and Identify

5 entries
  1. 04 Security Ownership, Governance, and Decision Rights
  2. 05 Asset, Data, and Dependency Inventory
  3. 06 Data Classification, Privacy, and Protection Requirements
  4. 07 Threat Modeling for Engineers
  5. 08 Risk Rating and Security Requirements

Part 3

Part III - Design Secure Systems

13 entries
  1. 09 Secure Architecture Review Process
  2. 10 Secure System Decomposition and Trust Boundaries
  3. 11 Identity and Authentication Architecture
  4. 12 Authorization and Access-Control Architecture
  5. 13 Secure API and Service Design
  6. 14 Cryptography and Key Management Architecture
  7. 15 Secrets Management
  8. 16 Network, Edge, and Zero-Trust Architecture
  9. 17 Multi-Tenancy and Isolation
  10. 18 Secure Cloud Architecture
  11. 19 Secure Kubernetes and Container Architecture
  12. 20 Resilience, Availability, and Recovery Architecture
  13. 21 Secure Observability, Logging, and Audit Architecture

Part 4

Part IV - Build Securely

9 entries
  1. 22 Secure Coding Foundations
  2. 23 Authentication Implementation
  3. 24 Authorization Implementation
  4. 25 Secure Data Storage, Databases, and Queries
  5. 26 Secure Frontend and Client-Side Engineering
  6. 27 Secure CI/CD and Release Engineering
  7. 28 Dependency and Software Supply-Chain Security
  8. 29 Infrastructure as Code and Configuration Security
  9. 30 Secure AI, ML, and LLM Implementation

Part 5

Part V - Review and Assure

5 entries
  1. 31 Security Code Review
  2. 32 Automated Security Testing
  3. 33 Manual Testing, Penetration Testing, and Red Teaming
  4. 34 Release Security Review and Production Readiness
  5. 35 Evidence, Assurance, and Audit Without Ceremony

Part 6

Part VI - Operate Securely

6 entries
  1. 36 Secure Production Access and Administration
  2. 37 Vulnerability Management and Patching
  3. 38 Configuration, Hardening, and Drift Management
  4. 39 Secure Backup, Restore, and Disaster Recovery Operations
  5. 40 Security Monitoring and Alert Operations
  6. 41 Secure Change Management and Operational Safety

Part 7

Part VII - Defend and Recover

6 entries
  1. 42 Threat-Informed Defense Strategy
  2. 43 Detection Engineering
  3. 44 Incident Response Operating Model
  4. 45 Incident Playbooks
  5. 46 Digital Forensics and Evidence Preservation
  6. 47 Recovery, Eradication, and Lessons Learned

Part 8

Part VIII - Domain Playbooks

10 entries
  1. 48 Web Application Security Playbook
  2. 49 API Security Playbook
  3. 50 Mobile Application Security Playbook
  4. 51 Cloud-Native Service Playbook
  5. 52 Kubernetes Platform Playbook
  6. 53 Data Platform and Analytics Playbook
  7. 54 AI/ML and LLM Application Playbook
  8. 55 Enterprise SaaS and Third-Party Integration Playbook
  9. 56 Corporate IT and Endpoint Playbook
  10. 57 OT, IoT, and Embedded Systems Playbook

Part 9

Part IX - Templates, Matrices, and Appendices

11 entries
  1. 58 Normative Requirement Style
  2. 59 Security Requirement Catalog Taxonomy
  3. 60 System Security Profile Template
  4. 61 Threat Scenario Template
  5. 62 Security Architecture Decision Record Template
  6. 63 Security Exception Template
  7. 64 Release Security Review Template
  8. 65 Incident Timeline Template
  9. 66 Detection Specification Template
  10. 67 Control-to-Evidence Matrix Template
  11. 68 Illustration and Visual Design Guide