IyaSec Blog

Notes on application security, API security, identity, and API management from the field. Articles are also published on Medium. Browse the archive by topic instead — 124 subjects.

Defense In Depth

  • Defense in Depth
  • Security Architecture
  • Security

“Defense in Depth” is the idea that no single security control is trusted to stop an attack. Instead, you stack multiple, independent layers so that if one fails, others still stand in the way.

Read article: Defense In Depth

Zero Trust Architecture

  • Application Security
  • Security Architecture
  • Zero Trust

Zero Trust Architecture (ZT or ZTA) is a security model / framework based on one simple idea: Never trust, always verify. From NIST, we have, the “… ZT approach is primarily focused on data and service protection but can and should be expanded to include all enterprise assets (devices,…

Read article: Zero Trust Architecture

A Vendor DMZ Pattern

  • API Gateways
  • API Management
  • Apigee

A long time ago, I was doing integration architecture work in the land of Enterprise Service Buses (ESBs) and API Gateways. Think IBM WebSphere DataPower and Apigee — I like to remember Apigee the way it was before it was integrated into GCP. After we had designed and built the ESB, we moved on to…

Read article: A Vendor DMZ Pattern

Internal Endpoints Must Have The Same Security Capabilities As External Endpoints

  • Environments
  • Security

In a previous post, we made a point of “Non-Prod Environments Must Have The Same Security Protections As Production”. In this post, we’re going to go one step further and say that your internal and external endpoints, generally, should have the same security capabilities baked into their security…

Read article: Internal Endpoints Must Have The Same Security Capabilities As External Endpoints

Looking for something specific? Browse all 124 topics.