Security from First Principles
Security Engineering for Fintech
คอร์ส Security Engineering แบบ end-to-end สำหรับ engineer ที่ต้องสร้างและดูแลระบบจริง เริ่มจาก security mindset, threat modeling และ cryptography ต่อด้วย identity, web, API, mobile, network และ AWS security ก่อนจบด้วย advanced attacks, software supply chain และการออกแบบระบบ Fintech ตั้งแต่ mobile app จนถึง production cloud
Course trail
เส้นทางการเรียน
Part 1 — Security Foundations
Part 2 — Identity & Web Security
Part 3 — API & Mobile Security
Part 4 — Network Security
Part 5 — Cloud Security on AWS
Part 6 — Advanced Security Engineering
How to Read This Course
- Part 1 อ่านเรียงลำดับ เพราะ threat modeling, cryptography และ Secure Development Lifecycle เป็นภาษากลางของทุก Part ที่ตามมา
- Part 2–4 ไล่ตามเส้นทางของ request จริง: identity และ browser → API และ mobile → network
- Part 5 นำ control เหล่านั้นไปวางบน AWS ตั้งแต่ account boundary จนถึง incident response
- Part 6 รวมช่องโหว่ระดับ advanced แล้วจบด้วย architecture และ go-live checklist ของระบบ Fintech
ตัวอย่างในคอร์สใช้สถานการณ์ทั่วไปจาก mobile wallet, public API, operations portal, double-entry ledger, KYC document service และ workload บน AWS โดยไม่มีชื่อองค์กรหรือ ระบบสมมติเฉพาะ เพื่อแสดงว่า control ในแต่ละชั้นเชื่อมกันอย่างไร ไม่ใช่เรียนช่องโหว่ เป็นรายการแยกจากกัน
คอร์สนี้เหมาะกับ software engineer, platform engineer, tech lead และ solution architect ที่คุ้นเคยกับ HTTP API, database และ cloud เบื้องต้น ไม่จำเป็นต้องมีพื้นฐาน Security มาก่อน
Scope and Safety
ตัวอย่างมีไว้เพื่อการเรียนรู้
ตัวอย่าง request, policy และ configuration ตัดรายละเอียดบางส่วนออกเพื่อให้เห็นแนวคิด ต้องผ่านการ review, test และปรับตาม threat model ของระบบจริงก่อนใช้ใน production เนื้อหาจะอธิบายวิธีป้องกันและการทดสอบเฉพาะระบบที่ได้รับอนุญาตให้ทดสอบเท่านั้น
[!CAUTION] Security control ไม่ได้แปลว่า compliant โดยอัตโนมัติ ส่วนที่กล่าวถึง PDPA, PCI DSS, KYC, audit และข้อกำกับของธุรกิจการเงินเป็น ข้อพิจารณาเชิงวิศวกรรม ไม่ใช่คำแนะนำทางกฎหมาย การตัดสินใจเรื่องขอบเขตข้อมูล, ระยะเวลาเก็บ, การรายงานเหตุ และการยอมรับความเสี่ยงต้องเป็นของผู้มีอำนาจจาก Security, Risk, Compliance และ Legal ขององค์กร
Reference Families
- NIST Cybersecurity Resource Center — security principles, identity, zero trust, Secure Software Development และ incident response
- OWASP — Top 10, ASVS, API Security, MASVS, MASTG และ Cheat Sheets
- IETF Datatracker — protocol standards เช่น TLS, OAuth และ JWT
- AWS Security Documentation — security controls และ shared responsibility ของบริการ AWS
เอกสารมาตรฐานและบริการ cloud เปลี่ยนได้เสมอ เนื้อหาจะหลีกเลี่ยงการจำหมายเลขเวอร์ชัน โดยไม่จำเป็น และระบุจุดที่ต้องตรวจ official documentation ของระบบที่ใช้งานจริง