StackPractices

security

Practical resources about security for software engineers.

109 results

Protecting Applications and Data

Security is not a checkbox — it is a mindset. From input validation and XSS prevention to secrets management and compliance frameworks, every layer of the stack needs defensive design.

Browse recipes for implementing Content Security Policy, encrypting data at rest and in transit, managing API keys, and conducting dependency audits. Guides also cover OWASP Top 10 mitigations and secure coding practices by language.

beginner

SSL Certificate Management Template

A template for tracking TLS/SSL certificate inventory, renewals, deployments, and expiration risks...

intermediate

Third-Party Vendor Assessment Template

A structured template for evaluating the security, compliance, and operational posture of...

beginner

User Access Audit Template

A template for reviewing and certifying user access rights across systems, applications, and data...

intermediate

Vulnerability Scan Report Template

A template for summarizing vulnerability scan findings, including asset coverage, severity...

advanced

API Authentication Design Template

Template for documenting API authentication flows and token lifecycle: auth scheme selection, token...

intermediate

API Security Review Template

A checklist template for reviewing API authentication, rate limiting, and OWASP compliance.

beginner

Data Classification Template

A template for classifying data as public, internal, confidential, or restricted with handling...

intermediate

Dependency Vulnerability Triage Template

Template for triaging CVEs by severity and impact: vulnerability scoring, exploitability...

advanced

Encryption Key Rotation: Runbook

Use this encryption key rotation runbook to rotate keys with zero downtime. Covers schedules,...

intermediate

Incident Response Playbook Template

A step-by-step playbook template for handling security incidents.

intermediate

OWASP Top 10 Remediation Checklist

Checklist for tracking OWASP Top 10 vulnerability remediation per application: risk assessment, fix...

intermediate

Penetration Test Remediation Template

A template for tracking security findings, assigning remediation owners, and validating fixes after...

intermediate

Secrets Rotation Runbook

Runbook for rotating secrets without downtime: secret inventory, dual-key rotation, AWS Secrets...

intermediate

Secrets Rotation Template

A template for scheduling and tracking the rotation of API keys, tokens, and certificates.

intermediate

Security Audit Checklist Template

A thorough checklist for conducting security audits of applications and infrastructure.

intermediate

Security Incident Response Template

A template for security incident response covering detection, classification, containment,...

intermediate

Security Review Checklist for PRs

Checklist for security checks during pull request review: input validation, authentication,...

intermediate

Vendor Risk Assessment Template

A template for evaluating third-party vendor security and operational risks.

intermediate

Vulnerability Management Template

A repeatable template for tracking vulnerabilities, assigning remediation owners, defining patching...

intermediate

Third-Party Dependency Audit Template

A template for auditing third-party dependencies: license compliance, security vulnerabilities,...

No results found.