Evidence search
Search
Search titles, summaries, topics, providers, authors, and the full open-access corpus.
Results for “rate”
125 publicationsDesign RDS IAM authentication around the connection pool
Generate IAM database tokens for the physical connections that need them, and keep token validity separate from the lifetime of an already-established SQL session.
Workload security · AWS · By Cloud Security DeskIsolate document parsing before RAG ingestion
Give document parsing a bounded worker, then admit its extracted content separately before embedding or indexing.
AI systems · Apache Tika / Kubernetes / gVisor · By Cloud Security DeskSeparate stopping a fault experiment from recovering the service
Plan AWS FIS around separate evidence for stopping execution, removing fault effects and accepting the recovered application.
Resilience · AWS · By Cloud Security DeskProve Identity Center permission changes reached every account
A permission-set change is complete only when the intended accounts, account-local policies, provisioning results and assignments have converged.
Identity & access · AWS · By Cloud Security DeskInvestigate denied access at an AWS VPC endpoint
Use CloudTrail network activity evidence to distinguish endpoint-policy violations from routing failures and downstream authorization problems.
Detection & response · AWS · By Cloud Security DeskFinish S3 multipart uploads with verifiable object integrity
Keep an owned part manifest and verify the complete object result, because successful part transfers and an initial HTTP 200 are not sufficient completion evidence.
Workload security · AWS · By Cloud Security DeskDecide what happens when an AI guardrail fails
Distinguish denial, incomplete checks and late results, then decide what may cross each protected release point.
AI systems · Algolia / TrueFoundry / Conductor · By Cloud Security DeskFind the EBS limit behind a slow database
Separate volume operation rate, byte rate, instance bandwidth and snapshot initialization before changing storage for a slow database.
Resilience · AWS · By Cloud Security DeskRestrict device code sign-in without breaking approved clients
Restrict device-code authentication through an explicit client and resource policy, and test the tracked sessions that can outlive the initial browser approval.
Identity & access · Microsoft / IETF · By Cloud Security DeskKeep GitHub audit streaming continuous across maintenance
Plan audit-stream maintenance around native history, pause buffers, receiver acceptance and duplicate-aware evidence receipts.
Detection & response · GitHub / AWS · By Cloud Security DeskGive Kubernetes admission webhooks an explicit failure contract
Treat an admission webhook as a control-plane dependency with explicit behavior for denial, call failure, mutation and the changes needed to repair it.
Workload security · Kubernetes · By Cloud Security DeskFind the shared dependencies behind a cloud outage
Use the June 2025 Google Cloud and Cloudflare reports to review shared runtime, control, identity and recovery dependencies without turning one outage into a provider ranking.
Resilience · Google Cloud / Cloudflare / AWS · By Cloud Security DeskPasskey deployment needs a recovery design
A workforce passkey rollout needs a recovery contract before broad enforcement. Separate credential custody, enrollment evidence and application sessions.
Identity & access · NIST / FIDO Alliance / Microsoft Entra · By Cloud Security DeskWorkload federation across clouds needs separate trust decisions
Cross-cloud federation adds trust decisions, not a portable permission system. Map each credential and resource grant before moving a runtime workload.
Identity & access · AWS / Google Cloud / Microsoft Entra · By Cloud Security DeskA defensible cloud patch queue starts with exploitation evidence
Join exploitation evidence to affected assets, exposure, ownership and verified remediation without turning CVSS, EPSS or a catalog entry into a complete risk score.
Detection & response · CISA / NIST / FIRST · By Cloud Security DeskChoosing isolation for a Kubernetes tenant
A namespace, a virtual control plane and a sandboxed runtime protect different boundaries. Start with tenant authority before choosing the cluster architecture.
Workload security · Kubernetes / gVisor / Kata Containers · By Cloud Security DeskSecurity evidence for AI release decisions
A release approval should identify the changed application, the claims its tests support and the evidence that expires when a model, prompt, data path or runtime changes.
AI systems · By Cloud Security DeskRecovery objectives that match the cloud service
Define the business function, outage clock, recoverable data and dependency assumptions before choosing a cloud disaster-recovery architecture.
Resilience · AWS / Azure / Google Cloud / NIST · By Cloud Security DeskEntra emergency access that survives normal sign-in failure
A second administrator account does not prove an independent recovery path. Test the credential, workstation, policy and alert dependencies together.
Identity & access · Microsoft Entra · By Cloud Security DeskWhat cloud snapshots cannot preserve
Separate live execution, persisted disk and provider records before an authorized containment decision destroys evidence that a snapshot cannot recover.
Detection & response · AWS / NIST · By Cloud Security DeskMake secret rotation reach every running application
Secret managers, mounted files, application memory and connection pools can disagree about the active credential. Test each stage before calling rotation complete.
Workload security · Kubernetes / AWS / Azure / Google Cloud · By Cloud Security DeskWhat coding benchmarks can prove about a model
A coding benchmark result depends on its tasks, harness and tests. A reproducible count of SWE-bench Verified shows why the denominator belongs beside every comparison.
AI systems · By Cloud Security DeskA controlled return from the SQS dead letter queue
Repair the failure, check consumer compatibility and return failed work with a bounded rate, observable stop conditions and business reconciliation.
Resilience · AWS · By Cloud Security DeskRotate Entra application certificates with proof of adoption
A renewed certificate can exist in Key Vault while a running client still uses the old key. Define the evidence that makes application rotation complete.
Identity & access · Microsoft Entra / Azure Key Vault · By Cloud Security Desk