Threat trước control
Bắt đầu bằng asset và trust boundary: user/API edge, workload identity, private data, admin path. Sau đó map threat vào layer phù hợp. IAM quyết định ai được làm gì; firewall quyết định network flow; Cloud Armor lọc HTTP edge; SCC cung cấp posture/finding visibility; logging/monitoring cung cấp evidence.
Incident runbook
Một runbook tốt có detect → validate → contain → eradicate/rotate → recover → verify → learn. Preserve timeline/log trước containment, tránh xóa dữ liệu hoặc cấp quyền rộng để chữa cháy. Credential leak cần revoke/rotate và truy vết usage; HTTP abuse cần edge policy/rate limit/health evidence.
Bài tập
Lập threat/control/evidence matrix cho public API và tabletop hai incident. Ghi action owner, severity, rollback, residual risk và cleanup. Nếu không có security sandbox, dùng policy/finding read-only và design có pass criteria.