Skip to content
Cloud Security DeskSearch
Menu

Evidence search

Search

Search titles, summaries, topics, providers, authors, and the full open-access corpus.

Results for “soft”

43 publications
Technical guideSource-based analysis

Entra emergency access that survives normal sign-in failure

A second administrator account does not prove an independent recovery path. Test the credential, workstation, policy and alert dependencies together.

Identity & access · Microsoft Entra · By Cloud Security Desk
Research noteSource-based analysis

What coding benchmarks can prove about a model

A coding benchmark result depends on its tasks, harness and tests. A reproducible count of SWE-bench Verified shows why the denominator belongs beside every comparison.

AI systems · By Cloud Security Desk
Technical guideSource-based analysis

Rotate Entra application certificates with proof of adoption

A renewed certificate can exist in Key Vault while a running client still uses the old key. Define the evidence that makes application rotation complete.

Identity & access · Microsoft Entra / Azure Key Vault · By Cloud Security Desk
Technical guideSource-based analysis

Where fine tuning data needs a trust boundary

A training dataset can preserve its checksum and still teach the wrong behavior. Admission controls need to separate origin, transformation, approved use and the model change they produce.

AI systems · By Cloud Security Desk
Technical guideSource-based analysis

Cloud incident severity needs a service impact model

Connect incident priority to service consequences, scope and time criticality while preserving evidence confidence and the authority to revise the decision.

Detection & response · NIST / FIRST · By Cloud Security Desk
Technical guideSource-based analysis

Turn SBOM and VEX records into patch decisions

A VEX statement is an assertion about a specific product and vulnerability. Match its scope and conditions before using it to suppress a finding.

Workload security · CISA / OpenVEX / CycloneDX / OASIS · By Cloud Security Desk
Technical guideSource-based analysis

Measure SCIM offboarding at the application

A successful provisioning update proves a directory action, not the end of every application session. Define and test the application's offboarding contract.

Identity & access · SCIM / Microsoft Entra · By Cloud Security Desk
Technical guideSource-based analysis

Keep database changes compatible with application rollback

Preserve an explicit relationship between old code and migrated state through additive changes, safe backfills, and a defined rollback window.

Resilience · Kubernetes / GitLab · By Cloud Security Desk
Technical guideSource-based analysis

Prove Azure Storage private access from DNS to authorization

Check the exact storage subresource, resolve its normal hostname from the application, and test public access and data permissions as separate boundaries.

Workload security · Azure · By Cloud Security Desk
Technical guideSource-based analysis

Build an Azure change record that survives the portal window

Activity Log records and resource logs answer different questions. Preserve the operation outcome, resource context and export scope needed for a later investigation.

Detection & response · Azure · By Cloud Security Desk
Technical guideSource-based analysis

Keep encryption keys recoverable with the data they protect

Trace each encrypted recovery point to its required key, usable lifecycle state, and restore permissions before retiring cryptographic dependencies.

Resilience · AWS / Azure · By Cloud Security Desk
Technical guideSource-based analysis

Verify container provenance before admitting a pinned image

Use the digest to identify the artifact, then check who signed it, which builder produced it, and which evidence survived promotion into the deployment registry.

Workload security · Kubernetes / Docker / Sigstore · By Cloud Security Desk
Technical guideSource-based analysis

Review the authority behind every Entra app consent

The permission name is only part of the decision. Review the access mode, resource scope, consenting authority and people who can change the application.

Identity & access · Microsoft Entra · By Cloud Security Desk
Technical guideSource-based analysis

Treat model downloads as software supply chain changes

Review weights, custom code, dependencies, and runtime authority as separate decisions before promoting a downloaded model into a trusted environment.

AI systems · Hugging Face · By Cloud Security Desk
Technical guideSource-based analysis

Investigate an Entra application through grants and sign-ins

A successful service-principal sign-in is one event in a larger sequence. Connect it to credential changes, permission grants and the resource involved.

Detection & response · Microsoft Entra · By Cloud Security Desk
Research noteSource-based analysis

Define the expiry boundary for Entra privileged access

PIM records activation and expiry, but the protected application still determines when changed authority takes effect. Review both sides of that boundary.

Identity & access · Microsoft Entra · By Cloud Security Desk
Technical guideSource-based analysis

Measure recovery by the service you can restore

Define application acceptance, recoverable data, and a complete timeline before treating a completed restore job as proof of recovery.

Resilience · AWS / PostgreSQL · By Cloud Security Desk
Technical guideSource-based analysis

Protect backup copies from the account that runs production

Map deletion authority, retention protection, keys, and recovery identities so a surviving backup has a usable path back to service.

Resilience · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Keep private documents out of shared RAG answers

Authorize retrieved documents before they enter model context, preserve permissions on chunks, and make source access changes visible in the retrieval path.

AI systems · Azure · By Cloud Security Desk