Evidence search
Search
Search titles, summaries, topics, providers, authors, and the full open-access corpus.
Results for “NIST”
41 publicationsPasskey deployment needs a recovery design
A workforce passkey rollout needs a recovery contract before broad enforcement. Separate credential custody, enrollment evidence and application sessions.
Identity & access · NIST / FIDO Alliance / Microsoft Entra · By Cloud Security DeskWorkload federation across clouds needs separate trust decisions
Cross-cloud federation adds trust decisions, not a portable permission system. Map each credential and resource grant before moving a runtime workload.
Identity & access · AWS / Google Cloud / Microsoft Entra · By Cloud Security DeskA defensible cloud patch queue starts with exploitation evidence
Join exploitation evidence to affected assets, exposure, ownership and verified remediation without turning CVSS, EPSS or a catalog entry into a complete risk score.
Detection & response · CISA / NIST / FIRST · By Cloud Security DeskChoosing isolation for a Kubernetes tenant
A namespace, a virtual control plane and a sandboxed runtime protect different boundaries. Start with tenant authority before choosing the cluster architecture.
Workload security · Kubernetes / gVisor / Kata Containers · By Cloud Security DeskSecurity evidence for AI release decisions
A release approval should identify the changed application, the claims its tests support and the evidence that expires when a model, prompt, data path or runtime changes.
AI systems · By Cloud Security DeskRecovery objectives that match the cloud service
Define the business function, outage clock, recoverable data and dependency assumptions before choosing a cloud disaster-recovery architecture.
Resilience · AWS / Azure / Google Cloud / NIST · By Cloud Security DeskEntra emergency access that survives normal sign-in failure
A second administrator account does not prove an independent recovery path. Test the credential, workstation, policy and alert dependencies together.
Identity & access · Microsoft Entra · By Cloud Security DeskWhat cloud snapshots cannot preserve
Separate live execution, persisted disk and provider records before an authorized containment decision destroys evidence that a snapshot cannot recover.
Detection & response · AWS / NIST · By Cloud Security DeskMake secret rotation reach every running application
Secret managers, mounted files, application memory and connection pools can disagree about the active credential. Test each stage before calling rotation complete.
Workload security · Kubernetes / AWS / Azure / Google Cloud · By Cloud Security DeskWhat coding benchmarks can prove about a model
A coding benchmark result depends on its tasks, harness and tests. A reproducible count of SWE-bench Verified shows why the denominator belongs beside every comparison.
AI systems · By Cloud Security DeskRotate Entra application certificates with proof of adoption
A renewed certificate can exist in Key Vault while a running client still uses the old key. Define the evidence that makes application rotation complete.
Identity & access · Microsoft Entra / Azure Key Vault · By Cloud Security DeskTesting Sigma detections before a backend change
Keep rule structure, field transformations, query conversion and event matching as separate checks when changing a Sigma detection backend.
Detection & response · SigmaHQ · By Cloud Security DeskDesign an outbound fetch service that contains SSRF
A URL check is only the first decision. The fetch worker must contact the approved destination, recheck redirects and limit the authority of every request.
Workload security · OWASP / IANA · By Cloud Security DeskWhere fine tuning data needs a trust boundary
A training dataset can preserve its checksum and still teach the wrong behavior. Admission controls need to separate origin, transformation, approved use and the model change they produce.
AI systems · By Cloud Security DeskError budgets for controlled service degradation
Protect essential work under load while counting rejected and degraded requests against the service promise that users were actually given.
Resilience · Google / Envoy · By Cloud Security DeskShort SSH certificates still need explicit access boundaries
An SSH certificate supplies bounded identity claims. The issuer, server, client and incident operator still make separate access decisions.
Identity & access · OpenSSH · By Cloud Security DeskCloud incident severity needs a service impact model
Connect incident priority to service consequences, scope and time criticality while preserving evidence confidence and the authority to revise the decision.
Detection & response · NIST / FIRST · By Cloud Security DeskA budget model for bounded AI inference
Request throttles, token quotas and billing alerts control different things. An inference service needs an admission decision that reserves bounded work and reconciles what actually ran.
AI systems · AWS / Kubernetes / vLLM · By Cloud Security DeskCertificate renewal under shorter validity limits
Use the public TLS issuance schedule to review authorization, renewal, deployment and independent verification of the certificate an endpoint actually serves.
Resilience · CA/Browser Forum / Let's Encrypt / AWS · By Cloud Security DeskMeasure SCIM offboarding at the application
A successful provisioning update proves a directory action, not the end of every application session. Define and test the application's offboarding contract.
Identity & access · SCIM / Microsoft Entra · By Cloud Security DeskPrepare cloud workloads for hybrid post-quantum TLS
Hybrid support in a library is not proof that every TLS hop uses it. Verify negotiation, compatibility and fallback while keeping certificate authentication separate.
Workload security · IETF / NIST / OpenSSL / Cloudflare · By Cloud Security DeskAn evidence plan for AI incident response
An AI incident record needs to connect the system version, context, output, downstream action and observed consequence. A saved prompt or a public report is only part of that evidence.
AI systems · By Cloud Security DeskCloud detection coverage after the ATT&CK data model change
Connect current ATT&CK strategies and analytics to available events, implemented rules and test evidence, while keeping taxonomy counts separate from protection.
Detection & response · MITRE · By Cloud Security DeskKeep database changes compatible with application rollback
Preserve an explicit relationship between old code and migrated state through additive changes, safe backfills, and a defined rollback window.
Resilience · Kubernetes / GitLab · By Cloud Security Desk