Skip to main content
Version: 1.0

Principles

  1. Defense in depth
    • No SPOF
    • Fail safe
  2. Least priviligeses
    • Only
    • Harden
    • Privileges Creep
    • Just in case
  3. Separation of Duties: we wont have any single point of control
    • No Single point of control
    • Collusion: the requester can't be an approver
  4. Secure by a design
    • It should be an AFTERethought that we put security in
    • Start to Finish
    • Secure out of the boxe (OOTB)
  5. KISS
    • Keep it simple and ...