Skip to content
Cloud Security DeskSearch
Menu

Evidence search

Search

Search titles, summaries, topics, providers, authors, and the full open-access corpus.

Results for “NIST”

41 publications
Technical guideSource-based analysis

Passkey deployment needs a recovery design

A workforce passkey rollout needs a recovery contract before broad enforcement. Separate credential custody, enrollment evidence and application sessions.

Identity & access · NIST / FIDO Alliance / Microsoft Entra · By Cloud Security Desk
Technical guideSource-based analysis

Workload federation across clouds needs separate trust decisions

Cross-cloud federation adds trust decisions, not a portable permission system. Map each credential and resource grant before moving a runtime workload.

Identity & access · AWS / Google Cloud / Microsoft Entra · By Cloud Security Desk
Technical guideSource-based analysis

A defensible cloud patch queue starts with exploitation evidence

Join exploitation evidence to affected assets, exposure, ownership and verified remediation without turning CVSS, EPSS or a catalog entry into a complete risk score.

Detection & response · CISA / NIST / FIRST · By Cloud Security Desk
Technical guideSource-based analysis

Choosing isolation for a Kubernetes tenant

A namespace, a virtual control plane and a sandboxed runtime protect different boundaries. Start with tenant authority before choosing the cluster architecture.

Workload security · Kubernetes / gVisor / Kata Containers · By Cloud Security Desk
Technical guideSource-based analysis

Security evidence for AI release decisions

A release approval should identify the changed application, the claims its tests support and the evidence that expires when a model, prompt, data path or runtime changes.

AI systems · By Cloud Security Desk
Technical guideSource-based analysis

Recovery objectives that match the cloud service

Define the business function, outage clock, recoverable data and dependency assumptions before choosing a cloud disaster-recovery architecture.

Resilience · AWS / Azure / Google Cloud / NIST · By Cloud Security Desk
Technical guideSource-based analysis

Entra emergency access that survives normal sign-in failure

A second administrator account does not prove an independent recovery path. Test the credential, workstation, policy and alert dependencies together.

Identity & access · Microsoft Entra · By Cloud Security Desk
Technical guideSource-based analysis

What cloud snapshots cannot preserve

Separate live execution, persisted disk and provider records before an authorized containment decision destroys evidence that a snapshot cannot recover.

Detection & response · AWS / NIST · By Cloud Security Desk
Technical guideSource-based analysis

Make secret rotation reach every running application

Secret managers, mounted files, application memory and connection pools can disagree about the active credential. Test each stage before calling rotation complete.

Workload security · Kubernetes / AWS / Azure / Google Cloud · By Cloud Security Desk
Research noteSource-based analysis

What coding benchmarks can prove about a model

A coding benchmark result depends on its tasks, harness and tests. A reproducible count of SWE-bench Verified shows why the denominator belongs beside every comparison.

AI systems · By Cloud Security Desk
Technical guideSource-based analysis

Rotate Entra application certificates with proof of adoption

A renewed certificate can exist in Key Vault while a running client still uses the old key. Define the evidence that makes application rotation complete.

Identity & access · Microsoft Entra / Azure Key Vault · By Cloud Security Desk
Technical guideSource-based analysis

Testing Sigma detections before a backend change

Keep rule structure, field transformations, query conversion and event matching as separate checks when changing a Sigma detection backend.

Detection & response · SigmaHQ · By Cloud Security Desk
Technical guideSource-based analysis

Design an outbound fetch service that contains SSRF

A URL check is only the first decision. The fetch worker must contact the approved destination, recheck redirects and limit the authority of every request.

Workload security · OWASP / IANA · By Cloud Security Desk
Technical guideSource-based analysis

Where fine tuning data needs a trust boundary

A training dataset can preserve its checksum and still teach the wrong behavior. Admission controls need to separate origin, transformation, approved use and the model change they produce.

AI systems · By Cloud Security Desk
Technical guideSource-based analysis

Error budgets for controlled service degradation

Protect essential work under load while counting rejected and degraded requests against the service promise that users were actually given.

Resilience · Google / Envoy · By Cloud Security Desk
Technical guideSource-based analysis

Short SSH certificates still need explicit access boundaries

An SSH certificate supplies bounded identity claims. The issuer, server, client and incident operator still make separate access decisions.

Identity & access · OpenSSH · By Cloud Security Desk
Technical guideSource-based analysis

Cloud incident severity needs a service impact model

Connect incident priority to service consequences, scope and time criticality while preserving evidence confidence and the authority to revise the decision.

Detection & response · NIST / FIRST · By Cloud Security Desk
Technical guideSource-based analysis

A budget model for bounded AI inference

Request throttles, token quotas and billing alerts control different things. An inference service needs an admission decision that reserves bounded work and reconciles what actually ran.

AI systems · AWS / Kubernetes / vLLM · By Cloud Security Desk
Technical guideSource-based analysis

Certificate renewal under shorter validity limits

Use the public TLS issuance schedule to review authorization, renewal, deployment and independent verification of the certificate an endpoint actually serves.

Resilience · CA/Browser Forum / Let's Encrypt / AWS · By Cloud Security Desk
Technical guideSource-based analysis

Measure SCIM offboarding at the application

A successful provisioning update proves a directory action, not the end of every application session. Define and test the application's offboarding contract.

Identity & access · SCIM / Microsoft Entra · By Cloud Security Desk
Technical guideSource-based analysis

Prepare cloud workloads for hybrid post-quantum TLS

Hybrid support in a library is not proof that every TLS hop uses it. Verify negotiation, compatibility and fallback while keeping certificate authentication separate.

Workload security · IETF / NIST / OpenSSL / Cloudflare · By Cloud Security Desk
Technical guideSource-based analysis

An evidence plan for AI incident response

An AI incident record needs to connect the system version, context, output, downstream action and observed consequence. A saved prompt or a public report is only part of that evidence.

AI systems · By Cloud Security Desk
Technical guideSource-based analysis

Cloud detection coverage after the ATT&CK data model change

Connect current ATT&CK strategies and analytics to available events, implemented rules and test evidence, while keeping taxonomy counts separate from protection.

Detection & response · MITRE · By Cloud Security Desk
Technical guideSource-based analysis

Keep database changes compatible with application rollback

Preserve an explicit relationship between old code and migrated state through additive changes, safe backfills, and a defined rollback window.

Resilience · Kubernetes / GitLab · By Cloud Security Desk