Skip to content
Cloud Security DeskSearch
Menu

Evidence search

Search

Search titles, summaries, topics, providers, authors, and the full open-access corpus.

Results for “Testing”

22 publications
Technical guideSource-based analysis

Passkey deployment needs a recovery design

A workforce passkey rollout needs a recovery contract before broad enforcement. Separate credential custody, enrollment evidence and application sessions.

Identity & access · NIST / FIDO Alliance / Microsoft Entra · By Cloud Security Desk
Technical guideSource-based analysis

Workload federation across clouds needs separate trust decisions

Cross-cloud federation adds trust decisions, not a portable permission system. Map each credential and resource grant before moving a runtime workload.

Identity & access · AWS / Google Cloud / Microsoft Entra · By Cloud Security Desk
Technical guideSource-based analysis

Security evidence for AI release decisions

A release approval should identify the changed application, the claims its tests support and the evidence that expires when a model, prompt, data path or runtime changes.

AI systems · By Cloud Security Desk
Technical guideSource-based analysis

Recovery objectives that match the cloud service

Define the business function, outage clock, recoverable data and dependency assumptions before choosing a cloud disaster-recovery architecture.

Resilience · AWS / Azure / Google Cloud / NIST · By Cloud Security Desk
Technical guideSource-based analysis

Entra emergency access that survives normal sign-in failure

A second administrator account does not prove an independent recovery path. Test the credential, workstation, policy and alert dependencies together.

Identity & access · Microsoft Entra · By Cloud Security Desk
Research noteSource-based analysis

What coding benchmarks can prove about a model

A coding benchmark result depends on its tasks, harness and tests. A reproducible count of SWE-bench Verified shows why the denominator belongs beside every comparison.

AI systems · By Cloud Security Desk
Technical guideSource-based analysis

Testing Sigma detections before a backend change

Keep rule structure, field transformations, query conversion and event matching as separate checks when changing a Sigma detection backend.

Detection & response · SigmaHQ · By Cloud Security Desk
Technical guideSource-based analysis

Short SSH certificates still need explicit access boundaries

An SSH certificate supplies bounded identity claims. The issuer, server, client and incident operator still make separate access decisions.

Identity & access · OpenSSH · By Cloud Security Desk
Technical guideSource-based analysis

A budget model for bounded AI inference

Request throttles, token quotas and billing alerts control different things. An inference service needs an admission decision that reserves bounded work and reconciles what actually ran.

AI systems · AWS / Kubernetes / vLLM · By Cloud Security Desk
Technical guideSource-based analysis

Prepare cloud workloads for hybrid post-quantum TLS

Hybrid support in a library is not proof that every TLS hop uses it. Verify negotiation, compatibility and fallback while keeping certificate authentication separate.

Workload security · IETF / NIST / OpenSSL / Cloudflare · By Cloud Security Desk
Technical guideSource-based analysis

The bottlenecks that shape a cloud DDoS response

Distinguish bandwidth, packet processing, connection state and application work before choosing a DDoS response or assuming the whole service path is protected.

Resilience · AWS / Azure / Google Cloud / Cloudflare · By Cloud Security Desk
Technical guideSource-based analysis

Cloud detection coverage after the ATT&CK data model change

Connect current ATT&CK strategies and analytics to available events, implemented rules and test evidence, while keeping taxonomy counts separate from protection.

Detection & response · MITRE · By Cloud Security Desk
Technical guideSource-based analysis

Model output needs its own trust boundary

A model can produce valid JSON containing an unauthorized identifier, an unsafe link or text that a renderer interprets as code. The application consuming that output owns the next trust decision.

AI systems · OpenAI · By Cloud Security Desk
Technical guideSource-based analysis

Prove Azure Storage private access from DNS to authorization

Check the exact storage subresource, resolve its normal hostname from the application, and test public access and data permissions as separate boundaries.

Workload security · Azure · By Cloud Security Desk
Technical guideSource-based analysis

Put enforceable boundaries around agent tool calls

Treat model proposals as requests for authority, then check the operation, resource, recipient, and approval at the point where a tool can create a side effect.

AI systems · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Make regional failover work without new infrastructure

Prepare capacity, dependencies, and the routing control path before an incident, then measure when clients reach an accepted recovery service.

Resilience · AWS · By Cloud Security Desk
Technical guideSource-based analysis

Require EC2 IMDSv2 without breaking container credentials

Separate metadata token requirements from response hop limits, then verify both existing instances and future launches before declaring the migration complete.

Workload security · AWS · By Cloud Security Desk
Research noteSource-based analysis

Define the expiry boundary for Entra privileged access

PIM records activation and expiry, but the protected application still determines when changed authority takes effect. Review both sides of that boundary.

Identity & access · Microsoft Entra · By Cloud Security Desk
Technical guideSource-based analysis

Measure recovery by the service you can restore

Define application acceptance, recoverable data, and a complete timeline before treating a completed restore job as proof of recovery.

Resilience · AWS / PostgreSQL · By Cloud Security Desk
Technical guideSource-based analysis

Test Kubernetes egress policies beyond a successful DNS lookup

Separate DNS resolution, source egress, destination ingress, and application identity when testing Kubernetes network isolation.

Workload security · Kubernetes / Cilium · By Cloud Security Desk
Technical guideSource-based analysis

Keep private documents out of shared RAG answers

Authorize retrieved documents before they enter model context, preserve permissions on chunks, and make source access changes visible in the retrieval path.

AI systems · Azure · By Cloud Security Desk
Research reportDesk publication

Qwen3.8-Flash-Next and GLM-5.3-Flash share a 3:1 long-context pattern

Both models replace most conventional attention layers with recurrent state and reserve sparse attention for periodic retrieval. Their differences lie in where they place capacity, how much neural computation they activate, and what their serving stacks must keep trustworthy.

AI systems · Resilience · By Umair Akbar and Ahmed Elshekh