Evidence search
Search
Search titles, summaries, topics, providers, authors, and the full open-access corpus.
Results for “Testing”
22 publicationsPasskey deployment needs a recovery design
A workforce passkey rollout needs a recovery contract before broad enforcement. Separate credential custody, enrollment evidence and application sessions.
Identity & access · NIST / FIDO Alliance / Microsoft Entra · By Cloud Security DeskWorkload federation across clouds needs separate trust decisions
Cross-cloud federation adds trust decisions, not a portable permission system. Map each credential and resource grant before moving a runtime workload.
Identity & access · AWS / Google Cloud / Microsoft Entra · By Cloud Security DeskSecurity evidence for AI release decisions
A release approval should identify the changed application, the claims its tests support and the evidence that expires when a model, prompt, data path or runtime changes.
AI systems · By Cloud Security DeskRecovery objectives that match the cloud service
Define the business function, outage clock, recoverable data and dependency assumptions before choosing a cloud disaster-recovery architecture.
Resilience · AWS / Azure / Google Cloud / NIST · By Cloud Security DeskEntra emergency access that survives normal sign-in failure
A second administrator account does not prove an independent recovery path. Test the credential, workstation, policy and alert dependencies together.
Identity & access · Microsoft Entra · By Cloud Security DeskWhat coding benchmarks can prove about a model
A coding benchmark result depends on its tasks, harness and tests. A reproducible count of SWE-bench Verified shows why the denominator belongs beside every comparison.
AI systems · By Cloud Security DeskTesting Sigma detections before a backend change
Keep rule structure, field transformations, query conversion and event matching as separate checks when changing a Sigma detection backend.
Detection & response · SigmaHQ · By Cloud Security DeskShort SSH certificates still need explicit access boundaries
An SSH certificate supplies bounded identity claims. The issuer, server, client and incident operator still make separate access decisions.
Identity & access · OpenSSH · By Cloud Security DeskA budget model for bounded AI inference
Request throttles, token quotas and billing alerts control different things. An inference service needs an admission decision that reserves bounded work and reconciles what actually ran.
AI systems · AWS / Kubernetes / vLLM · By Cloud Security DeskPrepare cloud workloads for hybrid post-quantum TLS
Hybrid support in a library is not proof that every TLS hop uses it. Verify negotiation, compatibility and fallback while keeping certificate authentication separate.
Workload security · IETF / NIST / OpenSSL / Cloudflare · By Cloud Security DeskThe bottlenecks that shape a cloud DDoS response
Distinguish bandwidth, packet processing, connection state and application work before choosing a DDoS response or assuming the whole service path is protected.
Resilience · AWS / Azure / Google Cloud / Cloudflare · By Cloud Security DeskCloud detection coverage after the ATT&CK data model change
Connect current ATT&CK strategies and analytics to available events, implemented rules and test evidence, while keeping taxonomy counts separate from protection.
Detection & response · MITRE · By Cloud Security DeskModel output needs its own trust boundary
A model can produce valid JSON containing an unauthorized identifier, an unsafe link or text that a renderer interprets as code. The application consuming that output owns the next trust decision.
AI systems · OpenAI · By Cloud Security DeskProve Azure Storage private access from DNS to authorization
Check the exact storage subresource, resolve its normal hostname from the application, and test public access and data permissions as separate boundaries.
Workload security · Azure · By Cloud Security DeskPut enforceable boundaries around agent tool calls
Treat model proposals as requests for authority, then check the operation, resource, recipient, and approval at the point where a tool can create a side effect.
AI systems · AWS · By Cloud Security DeskMake regional failover work without new infrastructure
Prepare capacity, dependencies, and the routing control path before an incident, then measure when clients reach an accepted recovery service.
Resilience · AWS · By Cloud Security DeskRequire EC2 IMDSv2 without breaking container credentials
Separate metadata token requirements from response hop limits, then verify both existing instances and future launches before declaring the migration complete.
Workload security · AWS · By Cloud Security DeskDefine the expiry boundary for Entra privileged access
PIM records activation and expiry, but the protected application still determines when changed authority takes effect. Review both sides of that boundary.
Identity & access · Microsoft Entra · By Cloud Security DeskMeasure recovery by the service you can restore
Define application acceptance, recoverable data, and a complete timeline before treating a completed restore job as proof of recovery.
Resilience · AWS / PostgreSQL · By Cloud Security DeskTest Kubernetes egress policies beyond a successful DNS lookup
Separate DNS resolution, source egress, destination ingress, and application identity when testing Kubernetes network isolation.
Workload security · Kubernetes / Cilium · By Cloud Security DeskKeep private documents out of shared RAG answers
Authorize retrieved documents before they enter model context, preserve permissions on chunks, and make source access changes visible in the retrieval path.
AI systems · Azure · By Cloud Security DeskQwen3.8-Flash-Next and GLM-5.3-Flash share a 3:1 long-context pattern
Both models replace most conventional attention layers with recurrent state and reserve sparse attention for periodic retrieval. Their differences lie in where they place capacity, how much neural computation they activate, and what their serving stacks must keep trustworthy.
AI systems · Resilience · By Umair Akbar and Ahmed Elshekh