Skip to main content

9 docs tagged with "sdlc"

View all tags

Portfolio App STRIDE Compliance Report

Executive compliance audit of the Portfolio App (Next.js) against the STRIDE threat model, mapped to source code, CI/CD controls, and operational procedures.

Portfolio App: Security

Security posture for the Portfolio App: threat surface, enforceable SDLC controls, and public-safe content and deployment practices.

Portfolio Docs: Security

Security posture for the Portfolio Docs App: threat surface, enforceable SDLC controls, supply chain hygiene, and public publication safety.

Security Posture and Secure SDLC

Threat models, secure SDLC controls, supply chain hygiene, and security evidence practices that demonstrate a security-first delivery process.

Threat Model: Portfolio App

STRIDE threat model for the Portfolio App (Next.js): trust boundaries, assets, threats, mitigations, and residual risks aligned to enterprise SDLC controls.

Threat Model: Portfolio Docs App

Threat model for the Docusaurus documentation platform, focused on supply chain risk, CI integrity, public content safety, and deployment surface controls.

Threat Models

Actionable threat models for portfolio systems: assets, trust boundaries, entry points, risks, mitigations, and validation procedures aligned to secure SDLC controls.