Evidence search
Search
Search titles, summaries, topics, providers, authors, and the full open-access corpus.
Results for “NIST”
41 publicationsMap every connection beyond the private AI endpoint
Trace inference, retrieval, tools, administration, and telemetry separately before describing an AI application as private.
AI systems · AWS · By Cloud Security DeskBuild an Azure change record that survives the portal window
Activity Log records and resource logs answer different questions. Preserve the operation outcome, resource context and export scope needed for a later investigation.
Detection & response · Azure · By Cloud Security DeskTrace Google service account impersonation across every hop
A short-lived token can carry a broad identity. Review who can mint it, which account it represents and whether the original caller remains visible.
Identity & access · Google Cloud · By Cloud Security DeskKeep encryption keys recoverable with the data they protect
Trace each encrypted recovery point to its required key, usable lifecycle state, and restore permissions before retiring cryptographic dependencies.
Resilience · AWS / Azure · By Cloud Security DeskPut enforceable boundaries around agent tool calls
Treat model proposals as requests for authority, then check the operation, resource, recipient, and approval at the point where a tool can create a side effect.
AI systems · AWS · By Cloud Security DeskFind the Google audit logs missing from your evidence window
Audit category, inherited configuration, destination and reader permissions all affect what an investigator can retrieve. Retention is only one part of the record.
Detection & response · Google Cloud · By Cloud Security DeskReview the authority behind every Entra app consent
The permission name is only part of the decision. Review the access mode, resource scope, consenting authority and people who can change the application.
Identity & access · Microsoft Entra · By Cloud Security DeskMake regional failover work without new infrastructure
Prepare capacity, dependencies, and the routing control path before an incident, then measure when clients reach an accepted recovery service.
Resilience · AWS · By Cloud Security DeskRequire EC2 IMDSv2 without breaking container credentials
Separate metadata token requirements from response hop limits, then verify both existing instances and future launches before declaring the migration complete.
Workload security · AWS · By Cloud Security DeskDefine the expiry boundary for Entra privileged access
PIM records activation and expiry, but the protected application still determines when changed authority takes effect. Review both sides of that boundary.
Identity & access · Microsoft Entra · By Cloud Security DeskMeasure recovery by the service you can restore
Define application acceptance, recoverable data, and a complete timeline before treating a completed restore job as proof of recovery.
Resilience · AWS / PostgreSQL · By Cloud Security DeskKeep MCP tokens bound to the intended resource
Keep token audiences, user consent, and downstream tool authority separate when reviewing a protected HTTP MCP service.
AI systems · MCP · By Cloud Security DeskTest Kubernetes egress policies beyond a successful DNS lookup
Separate DNS resolution, source egress, destination ingress, and application identity when testing Kubernetes network isolation.
Workload security · Kubernetes / Cilium · By Cloud Security DeskProtect backup copies from the account that runs production
Map deletion authority, retention protection, keys, and recovery identities so a surviving backup has a usable path back to service.
Resilience · AWS · By Cloud Security DeskChoose the S3 object events your investigation will need
CloudTrail event history is not an object-access ledger. Build selectors around the questions an investigation must answer, then test the exclusions.
Detection & response · AWS · By Cloud Security DeskLock GitHub deployment trust to the job you intend
A short-lived token still needs a narrow trust decision. Review the subject, deployment environment, reusable workflow and AWS role together.
Identity & access · AWS / GitHub · By Cloud Security DeskRecover the control plane before you need it
A recovery plan that depends on the compromised identity system is an aspiration. Build and test an independent administrative path.
Resilience · Identity & access · AWS / Azure / Google Cloud · By Umair Akbar and Ahmed Elshekh