Skip to content
Cybersecurity Engineering Handbook
Listening
Your library
Switch books
Cybersecurity Engineering Handbook
Listening now
Senior Engineering Interview Handbook
Listen
Solo Founder Product Engineering Handbook
Listen
Production Data Systems Handbook
Listen
AI Systems Handbook
Listen
The Rust Engineering Handbook
Open book
Performance Engineering and System Design Handbook
Listen
The Change Interface
Listen
CISSP Certification Guide
Open book
Project Management Mastery
Listen
Chapter
Preparing audio…
Read chapter
15s
30s
0:00
Choose Play when you are ready.
Text
Spoken text
Previous
Next
Playback speed
0.85×
1×
1.15×
1.25×
1.5×
2×
Sleep timer
Sleep
End of chapter
15 min
30 min
45 min
60 min
+5
Copy link
Volume
Spoken text is preparing…
Space
Play or pause
← →
Skip 15s / 30s
P N
Previous / next chapter
T
Spoken text
/
Search the text
M
Mute
0:00
/
0:00
Spoken text
Chapters
Follow spoken text
01
How to Use This Handbook
14:10
02
Security Principles Engineers Can Apply
17:50
03
The Minimum Security Bar
15:23
04
Security Ownership, Governance, and Decision Rights
14:33
05
Asset, Data, and Dependency Inventory
16:23
06
Data Classification, Privacy, and Protection Requirements
14:00
07
Threat Modeling for Engineers
15:41
08
Risk Rating and Security Requirements
18:31
09
Secure Architecture Review Process
14:25
10
Secure System Decomposition and Trust Boundaries
14:00
11
Identity and Authentication Architecture
16:34
12
Authorization and Access-Control Architecture
19:04
13
Secure API and Service Design
19:39
14
Cryptography and Key Management Architecture
22:07
15
Secrets Management
16:32
16
Network, Edge, and Zero-Trust Architecture
15:47
17
Multi-Tenancy and Isolation
14:20
18
Secure Cloud Architecture
18:04
19
Secure Kubernetes and Container Architecture
20:34
20
Resilience, Availability, and Recovery Architecture
15:52
21
Secure Observability, Logging, and Audit Architecture
15:31
22
Secure Coding Foundations
15:28
23
Authentication Implementation
17:48
24
Authorization Implementation
17:30
25
Secure Data Storage, Databases, and Queries
20:35
26
Secure Frontend and Client-Side Engineering
16:33
27
Secure CI/CD and Release Engineering
17:52
28
Dependency and Software Supply-Chain Security
16:03
29
Infrastructure as Code and Configuration Security
14:47
30
Secure AI, ML, and LLM Implementation
18:58
31
Security Code Review
15:55
32
Automated Security Testing
17:02
33
Manual Testing, Penetration Testing, and Red Teaming
17:34
34
Release Security Review and Production Readiness
13:25
35
Evidence, Assurance, and Audit Without Ceremony
14:34
36
Secure Production Access and Administration
14:53
37
Vulnerability Management and Patching
15:11
38
Configuration, Hardening, and Drift Management
16:56
39
Secure Backup, Restore, and Disaster Recovery Operations
17:23
40
Security Monitoring and Alert Operations
17:12
41
Secure Change Management and Operational Safety
14:35
42
Threat-Informed Defense Strategy
13:18
43
Detection Engineering
15:57
44
Incident Response Operating Model
19:04
45
Incident Playbooks
40:54
46
Digital Forensics and Evidence Preservation
13:49
47
Recovery, Eradication, and Lessons Learned
13:37
48
Web Application Security Playbook
20:14
49
API Security Playbook
16:51
50
Mobile Application Security Playbook
16:31
51
Cloud-Native Service Playbook
16:49
52
Kubernetes Platform Playbook
21:31
53
Data Platform and Analytics Playbook
14:36
54
AI/ML and LLM Application Playbook
20:27
55
Enterprise SaaS and Third-Party Integration Playbook
18:03
56
Corporate IT and Endpoint Playbook
21:58
57
OT, IoT, and Embedded Systems Playbook
19:17
58
Normative Requirement Style
10:43
59
Security Requirement Catalog Taxonomy
11:08
60
System Security Profile Template
7:07
61
Threat Scenario Template
7:36
62
Security Architecture Decision Record Template
5:59
63
Security Exception Template
4:41
64
Release Security Review Template
6:17
65
Incident Timeline Template
7:36
66
Detection Specification Template
7:13
67
Control-to-Evidence Matrix Template
5:28
68
Illustration and Visual Design Guide
12:50