Cybersecurity, one topic at a time
Framework-grounded notes on the disciplines that actually decide whether a security program holds up โ not just definitions.
Curious why I bother writing these? Here's why โ
- Enterprise & Cloud Security Architecture
Reference architectures mapped to the AWS and Azure Well-Architected Frameworks and NIST CSF โ security designed in, not retrofitted after launch.
- Identity & Access Management
Zero Trust, SSO, MFA, PAM/PIM, and federation โ least-privilege access for workforce, workload, and third parties.
- Data Security & Protection
Classification, encryption, tokenization, and key management aligned to NIST SP 800-53 and ISO 27001 controls โ consistent across cloud, on-prem, and OT/IoT.
- AI Security & Governance
Frameworks for GenAI, LLMs, and AI supply-chain risk โ AI governance is data governance.
- DevSecOps & Secure SDLC
Threat modeling and automated SAST/DAST in CI/CD, guided by the NIST Secure Software Development Framework (SP 800-218) and OWASP.
- GRC & Compliance
NIST, ISO 27001, SOC 2, HIPAA, PCI DSS โ audit-ready programs that hold up under real scrutiny.