Senior SecOps Engineer
Complete toolkit for Security Operations including vulnerability management, compliance verification, secure coding practices, and security automation.
Table of Contents
Trigger Terms
Use this skill when you encounter:
| Category |
Terms |
| Vulnerability Management |
CVE, CVSS, vulnerability scan, security patch, dependency audit, npm audit, pip-audit |
| OWASP Top 10 |
injection, XSS, CSRF, broken authentication, security misconfiguration, sensitive data exposure |
| Compliance |
SOC 2, PCI-DSS, HIPAA, GDPR, compliance audit, security controls, access control |
| Secure Coding |
input validation, output encoding, parameterized queries, prepared statements, sanitization |
| Secrets Management |
API key, secrets vault, environment variables, HashiCorp Vault, AWS Secrets Manager |
| Authentication |
JWT, OAuth, MFA, 2FA, TOTP, password hashing, bcrypt, argon2, session management |
| Security Testing |
SAST, DAST, penetration test, security scan, Snyk, Semgrep, CodeQL, Trivy |
| Incident Response |
security incident, breach notification, incident response, forensics, containment |
| Network Security |
TLS, HTTPS, HSTS, CSP, CORS, security headers, firewall rules, WAF |
| Infrastructure Security |
container security, Kubernetes security, IAM, least privilege, zero trust |
| Cryptography |
encryption at rest, encryption in transit, AES-256, RSA, key management, KMS |
| Monitoring |
security monitoring, SIEM, audit logging, intrusion detection, anomaly detection |
Core Capabilities
1. Security Scanner
Scan source code for security vulnerabilities including hardcoded secrets, SQL injection, XSS, command injection, and path traversal.
# Scan project for security issues
python scripts/security_scanner.py /path/to/project
# Filter by severity
python scripts/security_scanner.py /path/to/project --severity high
# JSON output for CI/CD
python scripts/security_scanner.py /path/to/project --json --output report.json
Detects:
- Hardcoded secrets (API keys, passwords, AWS credentials, GitHub tokens, private keys)
- SQL injection patterns (string concatenation, f-strings, template literals)
- XSS vulnerabilities (innerHTML assignment, unsafe DOM manipulation, React unsafe patterns)
- Command injection (shell=True, exec, eval with user input)
- Path traversal (file operations with user input)
2. Vulnerability Assessor
Scan dependencies for known CVEs across npm, Python, and Go ecosystems.
# Assess project dependencies
python scripts/vulnerability_assessor.py /path/to/project
# Critical/high only
python scripts/vulnerability_assessor.py /path/to/project --severity high
# Export vulnerability report
python scripts/vulnerability_assessor.py /path/to/project --json --output vulns.json
Scans:
package.json and package-lock.json (npm)
requirements.txt and pyproject.toml (Python)
go.mod (Go)
Output:
- CVE IDs with CVSS scores
- Affected package versions
- Fixed versions for remediation
- Overall risk score (0-100)
3. Compliance Checker
Verify security compliance against SOC 2, PCI-DSS, HIPAA, and GDPR frameworks.
# Check all frameworks
python scripts/compliance_checker.py /path/to/project
# Specific framework
python scripts/compliance_checker.py /path/to/project --framework soc2
python scripts/compliance_checker.py /path/to/project --framework pci-dss
python scripts/compliance_checker.py /path/to/project --framework hipaa
python scripts/compliance_checker.py /path/to/project --framework gdpr
# Export compliance report
python scripts/compliance_checker.py /path/to/project --json --output compliance.json
Verifies:
- Access control implementation
- Encryption at rest and in transit
- Audit logging
- Authentication strength (MFA, password hashing)
- Security documentation
- CI/CD security controls
Workflows
Workflow 1: Security Audit
Complete security assessment of a codebase.
# Step 1: Scan for code vulnerabilities
python scripts/security_scanner.py . --severity medium
# Step 2: Check dependency vulnerabilities
python scripts/vulnerability_assessor.py . --severity high
# Step 3: Verify compliance controls
python scripts/compliance_checker.py . --framework all
# Step 4: Generate combined report
python scripts/security_scanner.py . --json --output security.json
python scripts/vulnerability_assessor.py . --json --output vulns.json
python scripts/compliance_checker.py . --json --output compliance.json
Workflow 2: CI/CD Security Gate
Integrate security checks into deployment pipeline.
# .github/workflows/security.yml
name: Security Scan
on:
pull_request:
branches: [main, develop]
jobs:
security-scan:
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v4
- name: Set up Python
uses: actions/setup-python@v5
with:
python-version: '3.11'
- name: Security Scanner
run: python scripts/security_scanner.py . --severity high
- name: Vulnerability Assessment
run: python scripts/vulnerability_assessor.py . --severity critical
- name: Compliance Check
run: python scripts/compliance_checker.py . --framework soc2
Workflow 3: CVE Triage
Respond to a new CVE affecting your application.
1. ASSESS (0-2 hours)
- Identify affected systems using vulnerability_assessor.py
- Check if CVE is being actively exploited
- Determine CVSS environmental score for your context
2. PRIORITIZE
- Critical (CVSS 9.0+, internet-facing): 24 hours
- High (CVSS 7.0-8.9): 7 days
- Medium (CVSS 4.0-6.9): 30 days
- Low (CVSS < 4.0): 90 days
3. REMEDIATE
- Update affected dependency to fixed version
- Run security_scanner.py to verify fix
- Test for regressions
- Deploy with enhanced monitoring
4. VERIFY
- Re-run vulnerability_assessor.py
- Confirm CVE no longer reported
- Document remediation actions
Workflow 4: Incident Response
Security incident handling procedure.
PHASE 1: DETECT & IDENTIFY (0-15 min)
- Alert received and acknowledged
- Initial severity assessment (SEV-1 to SEV-4)
- Incident commander assigned
- Communication channel established
PHASE 2: CONTAIN (15-60 min)
- Affected systems identified
- Network isolation if needed
- Credentials rotated if compromised
- Preserve evidence (logs, memory dumps)
PHASE 3: ERADICATE (1-4 hours)
- Root cause identified
- Malware/backdoors removed
- Vulnerabilities patched (run security_scanner.py)
- Systems hardened
PHASE 4: RECOVER (4-24 hours)
- Systems restored from clean backup
- Services brought back online
- Enhanced monitoring enabled
- User access restored
PHASE 5: POST-INCIDENT (24-72 hours)
- Incident timeline documented
- Root cause analysis complete
- Lessons learned documented
- Preventive measures implemented
- Stakeholder report delivered
Tool Reference
security_scanner.py
| Option |
Description |
target |
Directory or file to scan |
--severity, -s |
Minimum severity: critical, high, medium, low |
--verbose, -v |
Show files as they're scanned |
--json |
Output results as JSON |
--output, -o |
Write results to file |
Exit Codes:
0: No critical/high findings
1: High severity findings
2: Critical severity findings
vulnerability_assessor.py
| Option |
Description |
target |
Directory containing dependency files |
--severity, -s |
Minimum severity: critical, high, medium, low |
--verbose, -v |
Show files as they're scanned |
--json |
Output results as JSON |
--output, -o |
Write results to file |
Exit Codes:
0: No critical/high vulnerabilities
1: High severity vulnerabilities
2: Critical severity vulnerabilities
compliance_checker.py
| Option |
Description |
target |
Directory to check |
--framework, -f |
Framework: soc2, pci-dss, hipaa, gdpr, all |
--verbose, -v |
Show checks as they run |
--json |
Output results as JSON |
--output, -o |
Write results to file |
Exit Codes:
0: Compliant (90%+ score)
1: Non-compliant (50-69% score)
2: Critical gaps (<50% score)
Security Standards
OWASP Top 10 Prevention
| Vulnerability |
Prevention |
| A01: Broken Access Control |
Implement RBAC, deny by default, validate permissions server-side |
| A02: Cryptographic Failures |
Use TLS 1.2+, AES-256 encryption, secure key management |
| A03: Injection |
Parameterized queries, input validation, escape output |
| A04: Insecure Design |
Threat modeling, secure design patterns, defense in depth |
| A05: Security Misconfiguration |
Hardening guides, remove defaults, disable unused features |
| A06: Vulnerable Components |
Dependency scanning, automated updates, SBOM |
| A07: Authentication Failures |
MFA, rate limiting, secure password storage |
| A08: Data Integrity Failures |
Code signing, integrity checks, secure CI/CD |
| A09: Security Logging Failures |
Comprehensive audit logs, SIEM integration, alerting |
| A10: SSRF |
URL validation, allowlist destinations, network segmentation |
Secure Coding Checklist
## Input Validation
- [ ] Validate all input on server side
- [ ] Use allowlists over denylists
- [ ] Sanitize for specific context (HTML, SQL, shell)
## Output Encoding
- [ ] HTML encode for browser output
- [ ] URL encode for URLs
- [ ] JavaScript encode for script contexts
## Authentication
- [ ] Use bcrypt/argon2 for passwords
- [ ] Implement MFA for sensitive operations
- [ ] Enforce strong password policy
## Session Management
- [ ] Generate secure random session IDs
- [ ] Set HttpOnly, Secure, SameSite flags
- [ ] Implement session timeout (15 min idle)
## Error Handling
- [ ] Log errors with context (no secrets)
- [ ] Return generic messages to users
- [ ] Never expose stack traces in production
## Secrets Management
- [ ] Use environment variables or secrets manager
- [ ] Never commit secrets to version control
- [ ] Rotate credentials regularly
Compliance Frameworks
SOC 2 Type II Controls
| Control |
Category |
Description |
| CC1 |
Control Environment |
Security policies, org structure |
| CC2 |
Communication |
Security awareness, documentation |
| CC3 |
Risk Assessment |
Vulnerability scanning, threat modeling |
| CC6 |
Logical Access |
Authentication, authorization, MFA |
| CC7 |
System Operations |
Monitoring, logging, incident response |
| CC8 |
Change Management |
CI/CD, code review, deployment controls |
PCI-DSS v4.0 Requirements
| Requirement |
Description |
| Req 3 |
Protect stored cardholder data (encryption at rest) |
| Req 4 |
Encrypt transmission (TLS 1.2+) |
| Req 6 |
Secure development (input validation, secure coding) |
| Req 8 |
Strong authentication (MFA, password policy) |
| Req 10 |
Audit logging (all access to cardholder data) |
| Req 11 |
Security testing (SAST, DAST, penetration testing) |
HIPAA Security Rule
| Safeguard |
Requirement |
| 164.312(a)(1) |
Unique user identification for PHI access |
| 164.312(b) |
Audit trails for PHI access |
| 164.312(c)(1) |
Data integrity controls |
| 164.312(d) |
Person/entity authentication (MFA) |
| 164.312(e)(1) |
Transmission encryption (TLS) |
GDPR Requirements
| Article |
Requirement |
| Art 25 |
Privacy by design, data minimization |
| Art 32 |
Security measures, encryption, pseudonymization |
| Art 33 |
Breach notification (72 hours) |
| Art 17 |
Right to erasure (data deletion) |
| Art 20 |
Data portability (export capability) |
Best Practices
Secrets Management
# BAD: Hardcoded secret
API_KEY = "sk-1234567890abcdef"
# GOOD: Environment variable
import os
API_KEY = os.environ.get("API_KEY")
# BETTER: Secrets manager
from your_vault_client import get_secret
API_KEY = get_secret("api/key")
SQL Injection Prevention
# BAD: String concatenation
query = f"SELECT * FROM users WHERE id = {user_id}"
# GOOD: Parameterized query
cursor.execute("SELECT * FROM users WHERE id = %s", (user_id,))
XSS Prevention
// BAD: Direct innerHTML assignment is vulnerable
// GOOD: Use textContent (auto-escaped)
element.textContent = userInput;
// GOOD: Use sanitization library for HTML
import DOMPurify from 'dompurify';
const safeHTML = DOMPurify.sanitize(userInput);
Authentication
// Password hashing
const bcrypt = require('bcrypt');
const SALT_ROUNDS = 12;
// Hash password
const hash = await bcrypt.hash(password, SALT_ROUNDS);
// Verify password
const match = await bcrypt.compare(password, hash);
Security Headers
// Express.js security headers
const helmet = require('helmet');
app.use(helmet());
// Or manually set headers:
app.use((req, res, next) => {
res.setHeader('X-Content-Type-Options', 'nosniff');
res.setHeader('X-Frame-Options', 'DENY');
res.setHeader('X-XSS-Protection', '1; mode=block');
res.setHeader('Strict-Transport-Security', 'max-age=31536000; includeSubDomains');
res.setHeader('Content-Security-Policy', "default-src 'self'");
next();
});
Reference Documentation
| Document |
Description |
references/security_standards.md |
OWASP Top 10, secure coding, authentication, API security |
references/vulnerability_management_guide.md |
CVE triage, CVSS scoring, remediation workflows |
references/compliance_requirements.md |
SOC 2, PCI-DSS, HIPAA, GDPR requirements |
Tech Stack
Security Scanning:
- Snyk (dependency scanning)
- Semgrep (SAST)
- CodeQL (code analysis)
- Trivy (container scanning)
- OWASP ZAP (DAST)
Secrets Management:
- HashiCorp Vault
- AWS Secrets Manager
- Azure Key Vault
- 1Password Secrets Automation
Authentication:
- bcrypt, argon2 (password hashing)
- jsonwebtoken (JWT)
- passport.js (authentication middleware)
- speakeasy (TOTP/MFA)
Logging & Monitoring:
- Winston, Pino (Node.js logging)
- Datadog, Splunk (SIEM)
- PagerDuty (alerting)
Compliance:
- Vanta (SOC 2 automation)
- Drata (compliance management)
- AWS Config (configuration compliance)
1---2name: senior-secops3description: Comprehensive SecOps skill for application security, vulnerability management, compliance, and secure development practices. Includes security scanning, vulnerability assessment, compliance checking, and security automation. Use when implementing security controls, conducting security audits, responding to vulnerabilities, or ensuring compliance requirements.4---56# Senior SecOps Engineer78Complete toolkit for Security Operations including vulnerability management, compliance verification, secure coding practices, and security automation.910---1112## Table of Contents1314- [Trigger Terms](#trigger-terms)15- [Core Capabilities](#core-capabilities)16- [Workflows](#workflows)17- [Tool Reference](#tool-reference)18- [Security Standards](#security-standards)19- [Compliance Frameworks](#compliance-frameworks)20- [Best Practices](#best-practices)2122---2324## Trigger Terms2526Use this skill when you encounter:2728| Category | Terms |29|----------|-------|30| **Vulnerability Management** | CVE, CVSS, vulnerability scan, security patch, dependency audit, npm audit, pip-audit |31| **OWASP Top 10** | injection, XSS, CSRF, broken authentication, security misconfiguration, sensitive data exposure |32| **Compliance** | SOC 2, PCI-DSS, HIPAA, GDPR, compliance audit, security controls, access control |33| **Secure Coding** | input validation, output encoding, parameterized queries, prepared statements, sanitization |34| **Secrets Management** | API key, secrets vault, environment variables, HashiCorp Vault, AWS Secrets Manager |35| **Authentication** | JWT, OAuth, MFA, 2FA, TOTP, password hashing, bcrypt, argon2, session management |36| **Security Testing** | SAST, DAST, penetration test, security scan, Snyk, Semgrep, CodeQL, Trivy |37| **Incident Response** | security incident, breach notification, incident response, forensics, containment |38| **Network Security** | TLS, HTTPS, HSTS, CSP, CORS, security headers, firewall rules, WAF |39| **Infrastructure Security** | container security, Kubernetes security, IAM, least privilege, zero trust |40| **Cryptography** | encryption at rest, encryption in transit, AES-256, RSA, key management, KMS |41| **Monitoring** | security monitoring, SIEM, audit logging, intrusion detection, anomaly detection |4243---4445## Core Capabilities4647### 1. Security Scanner4849Scan source code for security vulnerabilities including hardcoded secrets, SQL injection, XSS, command injection, and path traversal.5051```bash52# Scan project for security issues53python scripts/security_scanner.py /path/to/project5455# Filter by severity56python scripts/security_scanner.py /path/to/project --severity high5758# JSON output for CI/CD59python scripts/security_scanner.py /path/to/project --json --output report.json60```6162**Detects:**63- Hardcoded secrets (API keys, passwords, AWS credentials, GitHub tokens, private keys)64- SQL injection patterns (string concatenation, f-strings, template literals)65- XSS vulnerabilities (innerHTML assignment, unsafe DOM manipulation, React unsafe patterns)66- Command injection (shell=True, exec, eval with user input)67- Path traversal (file operations with user input)6869### 2. Vulnerability Assessor7071Scan dependencies for known CVEs across npm, Python, and Go ecosystems.7273```bash74# Assess project dependencies75python scripts/vulnerability_assessor.py /path/to/project7677# Critical/high only78python scripts/vulnerability_assessor.py /path/to/project --severity high7980# Export vulnerability report81python scripts/vulnerability_assessor.py /path/to/project --json --output vulns.json82```8384**Scans:**85- `package.json` and `package-lock.json` (npm)86- `requirements.txt` and `pyproject.toml` (Python)87- `go.mod` (Go)8889**Output:**90- CVE IDs with CVSS scores91- Affected package versions92- Fixed versions for remediation93- Overall risk score (0-100)9495### 3. Compliance Checker9697Verify security compliance against SOC 2, PCI-DSS, HIPAA, and GDPR frameworks.9899```bash100# Check all frameworks101python scripts/compliance_checker.py /path/to/project102103# Specific framework104python scripts/compliance_checker.py /path/to/project --framework soc2105python scripts/compliance_checker.py /path/to/project --framework pci-dss106python scripts/compliance_checker.py /path/to/project --framework hipaa107python scripts/compliance_checker.py /path/to/project --framework gdpr108109# Export compliance report110python scripts/compliance_checker.py /path/to/project --json --output compliance.json111```112113**Verifies:**114- Access control implementation115- Encryption at rest and in transit116- Audit logging117- Authentication strength (MFA, password hashing)118- Security documentation119- CI/CD security controls120121---122123## Workflows124125### Workflow 1: Security Audit126127Complete security assessment of a codebase.128129```bash130# Step 1: Scan for code vulnerabilities131python scripts/security_scanner.py . --severity medium132133# Step 2: Check dependency vulnerabilities134python scripts/vulnerability_assessor.py . --severity high135136# Step 3: Verify compliance controls137python scripts/compliance_checker.py . --framework all138139# Step 4: Generate combined report140python scripts/security_scanner.py . --json --output security.json141python scripts/vulnerability_assessor.py . --json --output vulns.json142python scripts/compliance_checker.py . --json --output compliance.json143```144145### Workflow 2: CI/CD Security Gate146147Integrate security checks into deployment pipeline.148149```yaml150# .github/workflows/security.yml151name: Security Scan152153on:154 pull_request:155 branches: [main, develop]156157jobs:158 security-scan:159 runs-on: ubuntu-latest160 steps:161 - uses: actions/checkout@v4162163 - name: Set up Python164 uses: actions/setup-python@v5165 with:166 python-version: '3.11'167168 - name: Security Scanner169 run: python scripts/security_scanner.py . --severity high170171 - name: Vulnerability Assessment172 run: python scripts/vulnerability_assessor.py . --severity critical173174 - name: Compliance Check175 run: python scripts/compliance_checker.py . --framework soc2176```177178### Workflow 3: CVE Triage179180Respond to a new CVE affecting your application.181182```1831. ASSESS (0-2 hours)184 - Identify affected systems using vulnerability_assessor.py185 - Check if CVE is being actively exploited186 - Determine CVSS environmental score for your context1871882. PRIORITIZE189 - Critical (CVSS 9.0+, internet-facing): 24 hours190 - High (CVSS 7.0-8.9): 7 days191 - Medium (CVSS 4.0-6.9): 30 days192 - Low (CVSS < 4.0): 90 days1931943. REMEDIATE195 - Update affected dependency to fixed version196 - Run security_scanner.py to verify fix197 - Test for regressions198 - Deploy with enhanced monitoring1992004. VERIFY201 - Re-run vulnerability_assessor.py202 - Confirm CVE no longer reported203 - Document remediation actions204```205206### Workflow 4: Incident Response207208Security incident handling procedure.209210```211PHASE 1: DETECT & IDENTIFY (0-15 min)212- Alert received and acknowledged213- Initial severity assessment (SEV-1 to SEV-4)214- Incident commander assigned215- Communication channel established216217PHASE 2: CONTAIN (15-60 min)218- Affected systems identified219- Network isolation if needed220- Credentials rotated if compromised221- Preserve evidence (logs, memory dumps)222223PHASE 3: ERADICATE (1-4 hours)224- Root cause identified225- Malware/backdoors removed226- Vulnerabilities patched (run security_scanner.py)227- Systems hardened228229PHASE 4: RECOVER (4-24 hours)230- Systems restored from clean backup231- Services brought back online232- Enhanced monitoring enabled233- User access restored234235PHASE 5: POST-INCIDENT (24-72 hours)236- Incident timeline documented237- Root cause analysis complete238- Lessons learned documented239- Preventive measures implemented240- Stakeholder report delivered241```242243---244245## Tool Reference246247### security_scanner.py248249| Option | Description |250|--------|-------------|251| `target` | Directory or file to scan |252| `--severity, -s` | Minimum severity: critical, high, medium, low |253| `--verbose, -v` | Show files as they're scanned |254| `--json` | Output results as JSON |255| `--output, -o` | Write results to file |256257**Exit Codes:**258- `0`: No critical/high findings259- `1`: High severity findings260- `2`: Critical severity findings261262### vulnerability_assessor.py263264| Option | Description |265|--------|-------------|266| `target` | Directory containing dependency files |267| `--severity, -s` | Minimum severity: critical, high, medium, low |268| `--verbose, -v` | Show files as they're scanned |269| `--json` | Output results as JSON |270| `--output, -o` | Write results to file |271272**Exit Codes:**273- `0`: No critical/high vulnerabilities274- `1`: High severity vulnerabilities275- `2`: Critical severity vulnerabilities276277### compliance_checker.py278279| Option | Description |280|--------|-------------|281| `target` | Directory to check |282| `--framework, -f` | Framework: soc2, pci-dss, hipaa, gdpr, all |283| `--verbose, -v` | Show checks as they run |284| `--json` | Output results as JSON |285| `--output, -o` | Write results to file |286287**Exit Codes:**288- `0`: Compliant (90%+ score)289- `1`: Non-compliant (50-69% score)290- `2`: Critical gaps (<50% score)291292---293294## Security Standards295296### OWASP Top 10 Prevention297298| Vulnerability | Prevention |299|--------------|------------|300| **A01: Broken Access Control** | Implement RBAC, deny by default, validate permissions server-side |301| **A02: Cryptographic Failures** | Use TLS 1.2+, AES-256 encryption, secure key management |302| **A03: Injection** | Parameterized queries, input validation, escape output |303| **A04: Insecure Design** | Threat modeling, secure design patterns, defense in depth |304| **A05: Security Misconfiguration** | Hardening guides, remove defaults, disable unused features |305| **A06: Vulnerable Components** | Dependency scanning, automated updates, SBOM |306| **A07: Authentication Failures** | MFA, rate limiting, secure password storage |307| **A08: Data Integrity Failures** | Code signing, integrity checks, secure CI/CD |308| **A09: Security Logging Failures** | Comprehensive audit logs, SIEM integration, alerting |309| **A10: SSRF** | URL validation, allowlist destinations, network segmentation |310311### Secure Coding Checklist312313```markdown314## Input Validation315- [ ] Validate all input on server side316- [ ] Use allowlists over denylists317- [ ] Sanitize for specific context (HTML, SQL, shell)318319## Output Encoding320- [ ] HTML encode for browser output321- [ ] URL encode for URLs322- [ ] JavaScript encode for script contexts323324## Authentication325- [ ] Use bcrypt/argon2 for passwords326- [ ] Implement MFA for sensitive operations327- [ ] Enforce strong password policy328329## Session Management330- [ ] Generate secure random session IDs331- [ ] Set HttpOnly, Secure, SameSite flags332- [ ] Implement session timeout (15 min idle)333334## Error Handling335- [ ] Log errors with context (no secrets)336- [ ] Return generic messages to users337- [ ] Never expose stack traces in production338339## Secrets Management340- [ ] Use environment variables or secrets manager341- [ ] Never commit secrets to version control342- [ ] Rotate credentials regularly343```344345---346347## Compliance Frameworks348349### SOC 2 Type II Controls350351| Control | Category | Description |352|---------|----------|-------------|353| CC1 | Control Environment | Security policies, org structure |354| CC2 | Communication | Security awareness, documentation |355| CC3 | Risk Assessment | Vulnerability scanning, threat modeling |356| CC6 | Logical Access | Authentication, authorization, MFA |357| CC7 | System Operations | Monitoring, logging, incident response |358| CC8 | Change Management | CI/CD, code review, deployment controls |359360### PCI-DSS v4.0 Requirements361362| Requirement | Description |363|-------------|-------------|364| Req 3 | Protect stored cardholder data (encryption at rest) |365| Req 4 | Encrypt transmission (TLS 1.2+) |366| Req 6 | Secure development (input validation, secure coding) |367| Req 8 | Strong authentication (MFA, password policy) |368| Req 10 | Audit logging (all access to cardholder data) |369| Req 11 | Security testing (SAST, DAST, penetration testing) |370371### HIPAA Security Rule372373| Safeguard | Requirement |374|-----------|-------------|375| 164.312(a)(1) | Unique user identification for PHI access |376| 164.312(b) | Audit trails for PHI access |377| 164.312(c)(1) | Data integrity controls |378| 164.312(d) | Person/entity authentication (MFA) |379| 164.312(e)(1) | Transmission encryption (TLS) |380381### GDPR Requirements382383| Article | Requirement |384|---------|-------------|385| Art 25 | Privacy by design, data minimization |386| Art 32 | Security measures, encryption, pseudonymization |387| Art 33 | Breach notification (72 hours) |388| Art 17 | Right to erasure (data deletion) |389| Art 20 | Data portability (export capability) |390391---392393## Best Practices394395### Secrets Management396397```python398# BAD: Hardcoded secret399API_KEY = "sk-1234567890abcdef"400401# GOOD: Environment variable402import os403API_KEY = os.environ.get("API_KEY")404405# BETTER: Secrets manager406from your_vault_client import get_secret407API_KEY = get_secret("api/key")408```409410### SQL Injection Prevention411412```python413# BAD: String concatenation414query = f"SELECT * FROM users WHERE id = {user_id}"415416# GOOD: Parameterized query417cursor.execute("SELECT * FROM users WHERE id = %s", (user_id,))418```419420### XSS Prevention421422```javascript423// BAD: Direct innerHTML assignment is vulnerable424// GOOD: Use textContent (auto-escaped)425element.textContent = userInput;426427// GOOD: Use sanitization library for HTML428import DOMPurify from 'dompurify';429const safeHTML = DOMPurify.sanitize(userInput);430```431432### Authentication433434```javascript435// Password hashing436const bcrypt = require('bcrypt');437const SALT_ROUNDS = 12;438439// Hash password440const hash = await bcrypt.hash(password, SALT_ROUNDS);441442// Verify password443const match = await bcrypt.compare(password, hash);444```445446### Security Headers447448```javascript449// Express.js security headers450const helmet = require('helmet');451app.use(helmet());452453// Or manually set headers:454app.use((req, res, next) => {455 res.setHeader('X-Content-Type-Options', 'nosniff');456 res.setHeader('X-Frame-Options', 'DENY');457 res.setHeader('X-XSS-Protection', '1; mode=block');458 res.setHeader('Strict-Transport-Security', 'max-age=31536000; includeSubDomains');459 res.setHeader('Content-Security-Policy', "default-src 'self'");460 next();461});462```463464---465466## Reference Documentation467468| Document | Description |469|----------|-------------|470| `references/security_standards.md` | OWASP Top 10, secure coding, authentication, API security |471| `references/vulnerability_management_guide.md` | CVE triage, CVSS scoring, remediation workflows |472| `references/compliance_requirements.md` | SOC 2, PCI-DSS, HIPAA, GDPR requirements |473474---475476## Tech Stack477478**Security Scanning:**479- Snyk (dependency scanning)480- Semgrep (SAST)481- CodeQL (code analysis)482- Trivy (container scanning)483- OWASP ZAP (DAST)484485**Secrets Management:**486- HashiCorp Vault487- AWS Secrets Manager488- Azure Key Vault489- 1Password Secrets Automation490491**Authentication:**492- bcrypt, argon2 (password hashing)493- jsonwebtoken (JWT)494- passport.js (authentication middleware)495- speakeasy (TOTP/MFA)496497**Logging & Monitoring:**498- Winston, Pino (Node.js logging)499- Datadog, Splunk (SIEM)500- PagerDuty (alerting)501502**Compliance:**503- Vanta (SOC 2 automation)504- Drata (compliance management)505- AWS Config (configuration compliance)