By the end
What you'll build
- Threat model a shared platform and state the trust boundaries and isolation assumptions it depends on
- Design least-privilege access for people, workloads and pipelines, including break-glass with an audit trail
- Operate a secret through its full lifecycle and respond to a leaked credential
- Write, test and roll out a policy as code check through warn, audit and enforce stages
- Verify artefact provenance and triage vulnerabilities without halting delivery
- Produce control evidence from normal platform operation rather than assembling it before an audit
Curriculum
What's inside
8 modules · 40 lessons
- 01
Threat modelling the platform
5 lessons- Threat modelling the platform itself, not only the applications on it
- Trust boundaries in a shared platform
- Build and pipeline systems as high-value targets
- Tenant isolation assumptions worth testing
- Platform threat modelling termsmatch pairs
- 02
Identity and access
5 lessons- Least privilege for people, workloads and pipelines
- Workload identity and short-lived credentials
- Role design and periodic privilege review
- Break-glass access with a reliable audit trail
- Three principals, three rulesfill blank
- 03
Secrets management
5 lessons- A secret's life: issue, use, rotate, revoke
- Keeping secrets out of code, images and logs
- Dynamic and short-lived credentials
- Detecting and responding to a leaked secret
- Rotating a secret that has escapedsequence order
- 04
Policy as code
5 lessons- Writing your first admission policy and testing it before it blocks anyone
- Authoring, testing and versioning policies
- Warn, audit and enforce as rollout stages
- Exceptions with an owner and an expiry date
- Turning on your first policyscenario
- 05
Supply chain integrity
5 lessons- Provenance: proving where an artefact came from
- Dependency and base image hygiene
- Signing and verification inside the pipeline
- Vulnerability triage that does not stop delivery
- Say what you can actually provematch pairs
- 06
Evidence and control frameworks
5 lessons- Producing control evidence as a by-product of the platform
- Mapping platform controls to a control framework for internal readiness
- Change records and separation of duties
- What auditors actually accept as evidence, and who issues certification
- Evidence, in the words a reviewer usesfill blank
- 07
Responding to a platform security event
5 lessons- Containment decisions when the platform itself is implicated
- Isolating a tenant, a pipeline or a credential
- Preserving evidence while restoring service
- Hardening after the event and closing the finding
- What each containment step leaves behindmatch pairs
- 08
Practice and check
5 lessons- Weakness and the control that answers itmatch pairs
- Shipping an admission policy without breaking everyonesequence order
- Precision about platform riskfill blank
- A credential in a pasted logscenario
- Course quizquiz
The shape of it
How this course works
Short lessons
40 lessons across 8 modules, each small enough to finish in one sitting.
Practice as you go
Every lesson ends with a small space for what you noticed — the doing is the learning.
Progress you can see
Your progress is saved lesson by lesson, ready whenever you come back.
Ready when you are.
Make an account and this course opens up — your progress is saved from the very first lesson.
