Security
Cryptography, certificates, and security frameworks
Standards
TLS 1.0 (RFC 2246)
by Internet Engineering Task Force
tls-1-0TLS 1.1 (RFC 4346)
by Internet Engineering Task Force
tls-1-1TLS 1.2 (RFC 5246)
by Internet Engineering Task Force
tls-1-2TLS 1.3 (RFC 8446)
by Internet Engineering Task Force
tls-1-3ISO/IEC 27001:2022
by ISO/IEC Joint Technical Committee
iso-27001-2022ISO/IEC 27002:2022
by ISO/IEC Joint Technical Committee
iso-27002-2022ISO/IEC 27017:2015 (Cloud Controls)
by ISO/IEC Joint Technical Committee
iso-27017-2015ISO/IEC 27018:2019 (Cloud PII)
by ISO/IEC Joint Technical Committee
iso-27018-2019ISO/IEC 27701:2019 (Privacy)
by ISO/IEC Joint Technical Committee
iso-27701-2019NIST SP 800-53 Rev 5
by National Institute of Standards and Technology
nist-800-53-r5NIST SP 800-171 Rev 3
by National Institute of Standards and Technology
nist-800-171-r3CIS Benchmarks Kubernetes v1.7
by Center for Internet Security
cis-kubernetes-1-7OWASP ASVS 4.0
by OWASP Foundation
owasp-asvs-4-0ISO/IEC 9594-8:2017 (X.509)
by ISO/IEC Joint Technical Committee
x509-2017PKCS #12 v1.1
by RSA Security
pkcs12-v1-1PKCS #7 / CMS (RFC 5652)
by Internet Engineering Task Force
pkcs7-rfc-5652RFC 6962 (Cert Transparency)
by Internet Engineering Task Force
rfc-6962RFC 5280 (PKIX)
by Internet Engineering Task Force
rfc-5280RFC 7515 (JWS)
by Internet Engineering Task Force
jws-rfc-7515ISO/IEC 9798-3:2014
by ISO/IEC Joint Technical Committee
iso-9798-3-2014ISO/IEC 15408-1:2022 (Common Criteria)
by ISO/IEC Joint Technical Committee
iso-15408-1-2022ISO/IEC 7816-4:2020 (Smart Cards)
by ISO/IEC Joint Technical Committee
iso-7816-4-2020ISO/IEC 29147:2018 (Vuln Disclosure)
by ISO/IEC Joint Technical Committee
iso-29147-2018ISO/IEC 30111:2019 (Vulnerability Handling)
by ISO/IEC Joint Technical Committee
iso-30111-2019MITRE CWE 4.11
by MITRE Corporation
cwe-4-11MITRE ATT&CK v14
by MITRE Corporation
mitre-attack-v14CAPEC v3.9
by MITRE Corporation
capec-3-9BSIMM13
by Synopsys
bsimm-13OWASP Top 10 2023
by OWASP Foundation
owasp-top10-2023RFC 9193 (SFrame Media Encryption)
by Internet Engineering Task Force
rfc-9193SLSA v1 (Supply-Chain Levels)
by Open Source Security Foundation
slsa-v1OpenSSF Scorecard 4.10
by Open Source Security Foundation
openssf-scorecard-4-10CycloneDX 1.6 (SBOM)
by Linux Foundation
cyclonedx-1-6SPDX 3.0
by Linux Foundation
spdx-3-0Best Practices
CycloneDX SBOM Specification
Lightweight Bill-of-Materials standard for software components, vulnerabilities, and licenses.
by OWASP FoundationInfrastructure-as-Code Security Playbook
Best practices for securing Terraform, CloudFormation, and ARM templates in CI/CD pipelines.
by HashiCorp & BridgecrewCNCF Cloud-Native Security Whitepaper
Guidance on building, shipping, and running secure cloud-native applications.
by CNCF Security TAGContainer Image Hardening Guide
Steps to build minimal, non-root, signed container images with SBOMs.
by CIS & DockerProducts & Technologies
HashiCorp Vault
Secrets management and data protection
Tutorials
Implementing OAuth 2.0 Authentication
Add OAuth 2.0 authentication to your application
Checklists
Security Migration Checklist
Security-focused checklist for any migration project