บทที่ 27 · Part 6 — Advanced Security Engineering
Fintech Security Architecture & Go-Live Checklist
Capstone architecture สำหรับ identity, transaction, data, AWS, supply chain, detection และ evidence-based security go-live decision
ระบบ Fintech เชื่อม identity, money movement, personal data, partner และ cloud control plane เข้าด้วยกัน ความผิดพลาดเพียงจุดเดียวอาจกลายเป็น account takeover, double spend, data breach หรือ outage บทสุดท้ายจึง รวม control จากทุกบทเป็น reference architecture และหลักฐานที่ใช้ตัดสินใจ go-live
Learning Outcomes
- สร้าง security architecture จาก asset, trust boundary และ transaction invariant ได้
- เชื่อม identity, web/API/mobile, network, AWS, data และ software supply chain controls ได้
- แปลง requirement เป็น test/evidence/owner ไม่หยุดที่คำว่า “รองรับ” ได้
- จัด risk-based go-live review และบันทึก residual-risk decision ได้
- วาง launch-day monitoring, rollback, incident communication และ post-launch review ได้
Scope and Assumptions
reference platform ในบทนี้มีองค์ประกอบทั่วไป:
- mobile application และ web application
- identity/authentication service
- public API/BFF และ internal services
- transaction orchestration กับ ledger
- KYC/document storage
- partner integration เช่น bank/payment network
- operations/admin portal
- AWS multi-account environment
- CI/CD, artifact registry และ observability/security systems
architecture นี้เป็น learning model ไม่ใช่แบบที่ใช้ได้กับทุก regulatory scope ต้องปรับตาม product, country, payment rail, data residency, availability objective และ risk appetite
Security Objectives
กำหนด objective ก่อนเลือก control:
- Account integrity: ผู้โจมตีไม่ยึด account ผ่าน auth/recovery/session path ได้ง่าย
- Transaction integrity: amount, currency, source, destination และ approval ไม่ถูกเปลี่ยนหรือ execute ซ้ำ
- Ledger integrity: balance invariant ถูก enforce แม้มี retry, race และ partial failure
- Data confidentiality: sensitive data ถูกใช้ตาม purpose และเปิดให้ principal ที่จำเป็น
- Service availability: critical flow ทน traffic surge, dependency failure และ DDoS ตาม objective
- Operational accountability: privileged/business decision trace กลับ actor และ evidence ได้
- Recoverability: restore service/data/key/dependency ได้ภายใน tested RTO/RPO
objective ต้องมี measurable acceptance criteria ไม่ใช่คำว่า “ปลอดภัยสูง”
Reference Architecture
diagram ไม่ได้แสดงทุก availability component แต่ทำให้เห็นว่ามีหลาย trust boundaries:
- untrusted client ถึง public edge
- edge ถึง application origin
- public/API tier ถึง identity/transaction/data services
- transaction domain ถึง external partner
- operations user ถึง privileged plane
- workload accounts ถึง security/log archive accounts
- CI/CD ถึง production deployment
แต่ละ boundary ต้องระบุ protocol, identity, authorization, data, rate/cost limit, timeout/retry, telemetry และ owner
Asset and Data Inventory
| Asset | Security concern | Example controls |
|---|---|---|
| Identity credential/session | account takeover, replay | passkey/MFA, session rotation/revoke, risk telemetry |
| Transaction instruction | tampering, replay, race | data binding, idempotency, authorization, invariant |
| Ledger entries | integrity, privileged mutation | append-oriented model, balanced entries, separation, audit |
| KYC documents | confidentiality, retention | isolated store, object authorization, encryption, lifecycle |
| Partner credential/key | impersonation, fraud | secret/KMS lifecycle, message signing, rotation |
| Signing/deploy identity | supply-chain compromise | short-lived identity, provenance, policy verification |
| Security logs | deletion, sensitive leakage | separate account, retention, least privilege, integrity |
| Recovery material | takeover, lockout | dual control, offline/out-of-band process, exercise |
inventory ต้องรวม copy ใน cache, backup, analytics, data lake, support tool และ third party ไม่ใช่เฉพาะ primary database
Trust Boundary Worksheet
สำหรับทุก data flow ให้ตอบ:
- source principal/workload คือใคร และ identity มาจากไหน
- destination resource/action คืออะไร
- ใครควบคุม network/client/runtime
- input ถูก parse/normalize ที่กี่ hop
- authorization ตรวจ subject-object-action-context ที่จุดใด
- message ถูก replay/reordered/delayed/duplicated ได้หรือไม่
- sensitive field ถูก log/cache/export ที่ใด
- failure/retry ทำให้ side effect ซ้ำหรือ state ค้างหรือไม่
- evidence ใดพิสูจน์ว่า control ทำงาน
worksheet ที่ตอบไม่ได้บ่งชี้ architecture gap ไม่ใช่เพียง documentation gap
Identity Architecture
Customer Identity
- password policy ตาม current guidance และ breached-password screening เมื่อใช้ password
- phishing-resistant option เช่น passkey
- step-up ตาม action/risk ไม่ใช่ sign-in อย่างเดียว
- anti-enumeration และ rate/abuse controls
- authenticator enrollment/replacement notification
- recovery ที่ไม่อ่อนกว่า primary authentication
- session/device inventory และ revoke path
- support override ผ่าน verified, audited workflow
รายละเอียดอยู่ใน Identity & Authentication, Strong Authentication & Account Recovery และ Session & Token Security
Workforce and Privileged Identity
- federation/central lifecycle ไม่มี shared admin identity
- phishing-resistant MFA สำหรับ privileged access
- role/permission ตาม duty และ environment
- just-in-time/time-bound elevation
- maker-checker สำหรับ high-impact action
- independent break-glass พร้อม alert/post-use review
- administrative action log ที่ operator แก้ไม่ได้
privileged portal ควรแยก origin/API/path จาก customer channel และไม่มี direct database mutation
Workload Identity
- dedicated role ต่อ service/environment
- temporary credential ไม่มี embedded long-lived key
- audience/action/resource scope
- constrained cross-account trust
- secret only เมื่อ target ไม่รองรับ workload federation
- rotation/revoke และ identity telemetry
AWS details อยู่ใน AWS IAM & Workload Identity
Authorization Model
authorization ต้อง enforce ที่ server ทุก object/action:
- customer อ่าน/แก้เฉพาะ resource ที่ relationship อนุญาต
- support role เห็น field เท่าที่ task ต้องใช้
- operator action มี reason/ticket/approval ตาม sensitivity
- service role เรียกเฉพาะ downstream action ที่จำเป็น
- tenant boundary อยู่ใน query/storage invariant ไม่พึ่ง UI filter
- export/bulk/search มี scope, purpose และ rate limit
ใช้ RBAC สำหรับ job function, ABAC สำหรับ context/attribute และ ReBAC สำหรับ relationship ตาม domain แต่ attribute/relationship source ต้องถูกป้องกัน รายละเอียดอยู่ใน Authorization & Access Control
Transaction Integrity
transaction request ควรมี canonical business intent:
- operation ID
- source account/wallet
- destination/beneficiary identity
- amount เป็น integer หน่วยสตางค์
- currency
- fee/exchange information
- purpose/reference เมื่อจำเป็น
- approval/risk context
- expiry/freshness
ผู้ใช้หรือ approver ต้องเห็นข้อมูลสำคัญที่ระบบจะ execute และการเปลี่ยน field ใดต้อง invalidate approval
Idempotency and Replay
- bind idempotency key กับ caller, operation และ canonical request hash
- create key/result/state transition แบบ atomic
- same key + different payload ต้อง reject
- webhook/message ตรวจ signature, timestamp, key ID และ replay uniqueness
- retention window ครอบคลุม real retry behavior
- idempotency ไม่แทน authentication หรือ nonce/freshness
Ledger Invariants
- double-entry/balanced-entry invariant ตาม ledger model
- unique business operation/reference
- atomic posting หรือ explicit pending/commit/reverse state machine
- immutable audit of correction/reversal แทนแก้ประวัติแบบเงียบ
- concurrency control ที่ database/durable boundary
- reconciliation กับ partner/source of truth
รายละเอียดอยู่ใน API Abuse & Transaction Integrity
Risk and Fraud Policy ต้องมี Human Owner
threshold, hold, manual review, beneficiary cooling period และ degraded-mode decision กระทบลูกค้าและธุรกิจ ต้องมี Product/Operations/Risk/Compliance authority ตาม scope ไม่ควรฝังเป็น technical default ที่ไม่มี owner
API Security
public/internal API ต้องมี:
- explicit schema และ reject unknown/ambiguous input ตาม contract
- authentication แยกจาก object/function/property authorization
- request/body/decompression/response/query complexity limits
- per-principal/object/tenant/global/concurrency/cost limits
- safe error และ no stack/secret leakage
- inventory/version/deprecation owner
- third-party API trust/timeout/retry/circuit behavior
- security event/correlation ID
OAuth/OIDC flow ต้องใช้ profile ที่เหมาะกับ client, PKCE/redirect/state/nonce validation และ audience/scopes ที่แคบ OAuth 2.1 ยังไม่ควรถูกอ้างว่าเป็น RFC final รายละเอียดอยู่ใน API Security Foundations และ OAuth, OIDC & Service Authentication
Web Security
web architecture ต้องพิจารณา:
- BFF/server session สำหรับ sensitive browser application เมื่อเหมาะสม
- Secure, HttpOnly, SameSite cookie และ CSRF defense
- output encoding ตาม context และ safe templating
- CSP/Trusted Types เป็น defense-in-depth ต่อ XSS
- clickjacking/frame policy
- CORS allowlist ตาม origin/method/header/credential semantics
- no sensitive token ใน browser storage เมื่อหลีกเลี่ยงได้
- secure upload/scanning/quarantine/download pipeline สำหรับเอกสาร
- cache control ป้องกันข้อมูลข้าม user/tenant
ดู Web Security Model, Injection & Input Security และ Browser & Content Security
Mobile Security
mobile client อยู่ใน attacker-controlled environment จึงไม่เก็บ server secret หรือ trust authorization decision ที่มีเฉพาะ client
- platform-backed Keystore/Keychain สำหรับ key/token ตาม risk
- biometric ผูก cryptographic operation เมื่อใช้ยืนยัน local key
- external user-agent + PKCE สำหรับ OAuth
- validate universal/app/deep links
- WebView bridge/navigation จำกัดอย่างเข้ม
- minimize backup, log, clipboard, screenshot, notification และ analytics leakage
- attestation/root detection/obfuscation เป็น risk signals ไม่ใช่ trust anchor
- pinning มี rotation/recovery strategy หาก threat model เลือกใช้
- secure signed update/no downgrade ตาม risk
verification ใช้ MASVS/MASTG ร่วมกับ backend/API standard ตาม Mobile Security Foundations และ Mobile Hardening & Testing
Data Protection
Customer and KYC Data
- classify fields/documents และ purpose
- object/tenant authorization ทุก read/write/export
- isolate KYC store/service path
- encrypt at rest/in transit พร้อม key policy
- malware/content pipeline สำหรับ upload
- no public bucket/origin
- pre-signed URL มี short expiry, scope และ signer permission
- retention/deletion/legal hold workflow
- backup restore พร้อม key dependency test
Logging and Analytics
- minimize/redact/tokenize sensitive fields
- no password, full token, secret หรือ raw payment data
- access/query/export audit
- retention by purpose
- production-to-analytics pipeline มี schema/field approval
- test deletion/subject workflow ครอบคลุม derived copy ตาม applicable policy
AWS controls อยู่ใน AWS Data & Workload Protection
Cryptographic Architecture
- TLS พร้อม hostname/service identity validation ทุก trust boundary
- approved maintained algorithms/libraries
- separate encryption, MAC และ signature objectives
- KMS/HSM ตาม key assurance/throughput/integration need
- envelope encryption และ encryption context ที่ไม่มี PII/secret
- key owner, cryptoperiod, rotate/revoke/disable/delete authority
- partner/message signature canonicalization และ replay state
- crypto-agility inventory สำหรับ algorithm/key migration
การเปิด KMS rotation ไม่ re-encrypt ข้อมูลเดิมและไม่ revoke compromised old material ดูรายละเอียดใน Cryptography, Keys & Secrets
AWS Organization Design
ขั้นต่ำที่ควรพิจารณา:
- management account ไม่มี workload/routine admin
- dedicated Log Archive และ Security Tooling accounts
- production/non-production/sandbox แยกตาม control profile
- workload/data boundary แยก account เพิ่มตาม sensitivity
- Organizations/OU/SCP guardrails แบบ staged
- account vending และ baseline-as-code
- root protection/recovery และ break-glass
- centralized service delegation
SCP เป็น maximum-permission guardrail ไม่ grant permission และไม่จำกัด management account ดู AWS Security Foundations & Multi-Account Design
Network Architecture
- trusted edge path: DNS → CDN/WAF/API Gateway/ALB → origin
- origin ไม่เปิด bypass path เมื่อ architecture รองรับ
- private application/data subnets ตาม effective routes
- SG แยก edge-to-api, api-to-service, service-to-data
- VPC endpoint พร้อม scoped endpoint/resource/IAM policies
- controlled egress สำหรับ partner/update/telemetry
- no public administrative port; audited session path
- Flow Logs/DNS/WAF/load balancer/firewall/application evidence
- DDoS load shedding และ critical-flow prioritization
private subnet/NAT/PrivateLink ไม่แทน authorization ดู AWS Network & Edge Security และ Network Defense, Detection & Zero Trust
Partner Integration
partner boundary ต้องกำหนด:
- network endpoint และ TLS service identity
- client/workload authentication
- message/request signature coverage
- clock/timestamp/nonce/replay window
- canonical request/response schema
- idempotency/reconciliation identifier
- timeout/retry/backoff/circuit breaker
- rate/quota และ partner outage behavior
- credential/key rotation overlap
- callback/webhook verification
- dispute/reconciliation/evidence process
IP allowlist เป็น defense-in-depth ไม่ใช่ partner identity เพียงอย่างเดียว
Software Delivery
Source and CI
- protected branch/tag, review และ security-sensitive CODEOWNERS
- phishing-resistant maintainer/admin access
- isolated untrusted pull-request builds
- pinned CI action/plugin/image
- short-lived scoped OIDC identity
- secret masking และ no production secret in build
- IaC/policy/code/dependency tests
Artifact and Deploy
- build once in ephemeral isolated builder
- SBOM และ provenance
- vulnerability/malware/license signals ตาม policy
- sign artifact
- verify digest, signer/issuer/claims/provenance ที่ admission
- promote immutable digest ไม่ rebuild/tag drift
- time-bound exception พร้อม owner
- rollback ใช้ known-good signed artifact
ดู Secure Development Lifecycle และ Advanced Attacks & Software Supply Chain
Detection Architecture
Cloud Signals
- organization CloudTrail trail + selected data events
- Config state/rules
- GuardDuty every intended Region/protection plan
- Macie targeted/automated discovery ตาม data scope
- Security Hub/Security Hub CSPM aggregation/correlation
- VPC Flow Logs, DNS, WAF และ workload/runtime telemetry
Business Security Signals
- auth/recovery/authenticator/session changes
- beneficiary/instruction/approval changes
- replay/idempotency/rate/concurrency denials
- unusual data search/export
- privileged override
- ledger correction/reversal/reconciliation mismatch
- partner signature/freshness failures
cloud finding ต้อง correlate กับ application actor/object/transaction context โดยไม่ log sensitive payload เกินจำเป็น ดู AWS Logging, Detection & Incident Response
Incident Response Architecture
เตรียม runbook อย่างน้อย:
- customer account takeover
- workforce/privileged identity compromise
- workload role/secret compromise
- public data exposure/exfiltration
- ledger/transaction integrity incident
- malicious deployment/supply-chain compromise
- DDoS/dependency/partner outage
- logging/detection failure
- KMS key disable/delete/compromise
- ransomware/operator deletion และ restore
แต่ละ runbook ระบุ evidence, authority, reversible containment, customer/business impact, communication และ recovery validation
Security Requirements Matrix
ทุก requirement ควรมีรูปแบบ:
| Field | ความหมาย |
|---|---|
| ID | stable requirement identifier |
| Asset/threat | สิ่งที่ป้องกันและเหตุโจมตี |
| Requirement | behavior ที่ต้องเกิด/ห้ามเกิด |
| Control owner | ผู้สร้าง/ดูแล control |
| Test | วิธี positive/negative/adversarial verification |
| Evidence | result/config/log/report ที่ review ได้ |
| Runtime signal | วิธีตรวจ drift/failure/attack |
| Exception | reason, compensating control, owner, expiry |
ตัวอย่าง requirement ที่ตรวจได้:
SEC-TX-007
Threat: duplicate or concurrent debit violates balance invariant
Requirement: one operation ID posts at most once and balance never crosses allowed boundary
Test: concurrent integration test with retries and storage-level failure injection
Evidence: test result, database constraint/state-machine definition, deployment revision
Runtime signal: duplicate-key conflict rate, invariant monitor, reconciliation mismatch
คำว่า “ใช้ WAF”, “เข้ารหัส” หรือ “มี MFA” เป็น control statement ที่ยังไม่บอก objective, scope และ evidence
Verification Strategy
| Layer | Verification |
|---|---|
| Requirement/design | threat model, abuse cases, architecture review |
| Code | peer review, SAST, secret scan, unit/property tests |
| Dependency/artifact | SCA, SBOM, image scan, signature/provenance verification |
| API/web | ASVS-based tests, DAST, authz/negative/abuse tests |
| Mobile | MASVS requirements + MASTG static/dynamic tests |
| Infrastructure | IaC tests, policy analysis, config drift, attack-path review |
| Runtime | detection simulation, load/failure/security game day |
| Recovery | backup/key/restore and incident tabletop |
automated scan ไม่แทน manual architecture/business-logic review และ penetration test ไม่แทน continuous controls
Performance and Security
security limit ต้องทดสอบกับ capacity:
- login/OTP/step-up vendor quota
- API per-user/global/cost/concurrency limits
- KMS/Secrets Manager/service quotas
- database connection/lock contention
- queue lag และ retry storm
- WAF/edge/origin capacity
- partner timeout/rate/outage
- security log volume/query/delivery
failure mode ต้องไม่เปิด permission กว้าง, skip signature/authorization หรือ execute transaction ซ้ำ
Go-Live Gates
Gate 1 — Scope and Ownership
- architecture/data-flow diagrams เป็น revision ปัจจุบัน
- assets/data classification/third parties ครบตาม known scope
- production account/service/Region owners ชัด
- security requirement และ risk register มี stable IDs
- legal/compliance/privacy interpretation มี responsible authority
Gate 2 — Identity and Transaction
- customer/admin/workload identities ใช้ intended production paths
- recovery, support override และ break-glass tested
- object/function/property authorization negative tests ผ่าน
- transaction-data binding/idempotency/replay/race invariants ผ่าน
- ledger/reconciliation/approval flows มี business owner sign-off
Gate 3 — Data and Cloud
- public/cross-account/data export paths reviewed
- KMS/key/secret rotation-recovery dependencies tested
- backup restore วัด RTO/RPO จริง
- accounts/SCP/IAM/network/endpoints/egress ตรง baseline
- production logging/detection enrollment ครบทุก intended Region
Gate 4 — Software and Operations
- source/CI/artifact/deploy verification enforce ใน production
- critical/high findings resolved หรือมี approved exception
- capacity, abuse, DDoS และ dependency failure tested
- dashboards/alerts/on-call/runbooks พร้อม
- rollback ใช้ artifact/config/data procedure ที่ทดสอบแล้ว
Gate 5 — Incident and Decision
- tabletop ครอบคลุม high-impact scenario
- contacts/authority/out-of-band channel ยืนยันแล้ว
- open residual risks มี likelihood/impact/compensating control/expiry
- launch/rollback criteria มีผู้ตัดสิน
- evidence package ถูก review และเก็บตาม policy
Detailed Go-Live Checklist
Governance and Threat Model
- product/data/architecture scope และ assumptions เป็นปัจจุบัน
- asset, actor, dependency และ trust boundary มี owner
- STRIDE/abuse/business-fraud scenarios ถูกจัดลำดับ
- control map เชื่อม requirement → test → evidence → runtime signal
- exception ทุกตัวมี residual-risk owner และ expiry
- no tool/service ถูกอ้างว่า “ทำให้ผ่าน compliance” โดยไม่มี scope/evidence review
Identity and Access
- workforce/admin ใช้ federation และ phishing-resistant MFA ตาม risk
- customer MFA/passkey/recovery/session paths ผ่าน takeover tests
- dormant/terminated identity lifecycle ทำงาน
- role/permission/trust/
PassRole/cross-account paths reviewed - no shared/embedded long-lived production key
- privileged elevation/maker-checker/break-glass time-bound และ audited
- Access Analyzer/policy tests ครอบคลุม allow และ deny path
Transaction and Ledger
- canonical instruction bind amount/currency/source/destination/fee/operation
- approval invalidated เมื่อ protected transaction data เปลี่ยน
- idempotency bind caller + operation + request hash แบบ atomic
- replay state/window และ webhook/message signature tested
- concurrent/failure/retry tests รักษา ledger invariant
- duplicate/reversal/refund/dispute flows มี explicit state machine
- reconciliation mismatch มี alert, owner และ correction policy
Web, API and Mobile
- schema validation, output encoding และ safe error ครบ boundary
- XSS/CSRF/CORS/CSP/clickjacking/cache controls verified
- BOLA/function/property authorization มี negative tests
- body/query/decompression/rate/cost/concurrency limits tested
- OAuth/OIDC redirect/PKCE/state/nonce/issuer/audience/type checks ผ่าน
- mobile storage/link/WebView/backup/log/clipboard/SDK exposure reviewed
- attestation/root/pinning signals ไม่ถูกใช้เป็น authorization proof เดี่ยว
- file upload quarantine/scan/download authorization tested
Data, Keys and Secrets
- sensitive fields/documents มี purpose, location, retention และ deletion owner
- encryption at rest/in transit ไม่ถูกใช้แทน authorization
- KMS key policy/grant/context/admin-user separation reviewed
- key disable/delete/compromise และ restore procedure tested
- secret rotation ครอบคลุม consumer cache/overlap/revoke/rollback
- S3 public/access point/policy/pre-signed URL/version/Object Lock paths reviewed
- database snapshot/export/backup/cross-account paths restricted
- log/analytics/crash/support tools ไม่มี sensitive data เกิน purpose
AWS and Network
- management, Log Archive, Security Tooling และ workload accounts แยกตาม design
- root protection/contact/recovery และ organization account inventory ครบ
- SCP/landing-zone baseline ผ่าน staged test และ drift reconciliation
- effective routes, SG, NACL, endpoint, edge และ origin paths reviewed
- origin/admin/data plane ไม่มี unintended public/bypass route
- private endpoint policies จำกัด principal/action/resource
- egress ครอบคลุม route/DNS/firewall/proxy/identity/destination validation
- Network Firewall path symmetric และ failure mode tested
- DDoS/load shedding/degraded mode มี business approval
Software Supply Chain
- maintainer/repository/CI identities protected และ scoped
- untrusted build แยกจาก release secret/environment
- dependencies/actions/images pinned และมี update process
- build ephemeral/isolated และ produce artifact ครั้งเดียว
- SBOM/provenance/signature/scan ถูกสร้างและเก็บกับ digest
- deployment verify trusted signer/issuer/claims/provenance/digest
- production admission/bypass/break-glass audited
- rollback artifact เป็น known-good immutable digest
Detection and Response
- organization CloudTrail + required data events ส่ง Log Archive สำเร็จ
- Config/GuardDuty/Macie/Security Hub coverage ทุก account/Region ที่ตั้งใจ
- Flow/DNS/WAF/edge/workload/application logs มี retention/access/privacy policy
- delivery health และ control-disable change alert
- auth/transaction/data/admin security events มี correlation ID
- critical detection ทุกตัวมี owner/runbook/test/containment authority
- evidence store และ integrity/retrieval validation exercised
- incident access ใช้ได้เมื่อ primary IdP/control path ล่ม
- containment preserve evidence และ rollback ได้เมื่อเหมาะสม
Reliability and Recovery
- load/capacity/soak tests รวม security controls
- dependency timeout/retry/backoff/circuit/quota behavior tested
- queue/retry storm ไม่ bypass limit หรือ duplicate side effect
- backup restore รวม key, IAM, network, config และ application dependency
- measured RTO/RPO ตรง approved objective
- Region/account/partner outage runbook tested ตาม scope
- rollback criteria, data migration compatibility และ decision owner ชัด
Evidence Package
ก่อน review ควรรวม link/reference ไม่ copy secret:
- architecture/data-flow/threat model revision
- requirements/control/evidence matrix
- IAM/network/KMS/data-policy review results
- ASVS/MASVS/API verification records
- code/dependency/image/IaC/SBOM/provenance results
- performance/failure/concurrency/security test results
- detection simulation และ tabletop report
- backup/restore RTO/RPO evidence
- open findings/exceptions/risk acceptance
- launch/rollback/on-call/communication plan
evidence ต้อง reproducible และผูกกับ version/environment ที่จะ deploy รายงานจาก artifact หรือ configuration เก่า ไม่ใช่หลักฐานของ release ปัจจุบัน
Residual Risk Decision
ไม่มี launch ที่ risk เป็นศูนย์ รายการที่ยังเปิดควรบันทึก:
- risk statement: threat → vulnerability/control gap → impact
- affected assets/users/flows
- likelihood/impact และ uncertainty
- current/compensating controls
- evidence และ blind spots
- remediation owner/date
- exception expiry/review trigger
- accept/mitigate/avoid/transfer decision
- accountable authority
Engineer ไม่ควร Accept Business/Compliance Risk แทนผู้มีอำนาจ
หน้าที่ทางเทคนิคคือให้ข้อมูลที่ตรวจสอบได้ อธิบาย scenario/impact/control gap และเสนอทางเลือก การรับ residual risk ที่กระทบเงิน ข้อมูลส่วนบุคคล กฎหมาย หรือ availability ต้องมีผู้รับผิดชอบตาม governance
Launch-Day Plan
Before Launch
- freeze window/change ownership ตาม risk
- verify artifact digest/config/migration
- confirm on-call, war room และ out-of-band contacts
- check dashboards/log delivery/detection test event
- verify backup/rollback state
- confirm partner capacity/status/credential
- record go/no-go authority และ time
During Launch
- deploy staged/canary เมื่อ architecture รองรับ
- monitor auth success/failure, authorization denial, transaction/error/latency
- monitor idempotency/replay/invariant/reconciliation signals
- monitor edge/WAF/rate/DDoS/cost/dependency
- monitor CloudTrail/config/security findings
- pause/rollback ตาม pre-defined criteria
After Launch
- verify no security control/telemetry silently degraded
- reconcile transactions/data migration
- review new permission/network/data paths
- close หรือ carry forward findings อย่างมี owner
- capture incident/near-miss/operational learning
- schedule 24-hour, 7-day และ 30-day review ตาม risk
Continuous Security after Go-Live
go-live เป็น checkpoint ไม่ใช่ปลายทาง:
- threat model เมื่อ feature/data/partner/architecture เปลี่ยน
- patch/dependency/key/secret/certificate lifecycle
- access/exception/account/resource review
- periodic authorization/abuse/mobile verification
- detection regression/purple-team/tabletop
- backup/restore และ break-glass exercise
- metric review: coverage, finding age, exception age, detection/containment/recovery time
- post-incident corrective actions ที่มี owner/due date
Security program ที่ดีลดเวลาระหว่าง drift/attack กับการค้นพบและจำกัดผล ไม่ใช่คาดหวังว่าจะป้องกันทุกเหตุ
Framework Mapping
ใช้ framework หลายตัวตาม scope:
- NIST CSF 2.0: Govern, Identify, Protect, Detect, Respond, Recover
- NIST SSDF: secure software development practices
- OWASP ASVS 5.0: web/application/API verification requirements
- OWASP API Security Top 10:2023: API risk awareness
- OWASP MASVS/MASTG: mobile requirements และ test evidence
- AWS Well-Architected Security Pillar: cloud architecture review lens
- OWASP Top 10:2025: application risk awareness/communication
framework หนึ่งไม่แทนอีก framework และไม่มีรายการใดรับรอง compliance โดยอัตโนมัติ
Final Review
- architecture อธิบาย asset, identity, trust boundary, data และ transaction invariant ได้
- prevention, detection, response และ recovery เชื่อมกัน
- control สำคัญมี negative/adversarial/failure test
- cloud และ application telemetry ครอบคลุม scenario ที่จัดลำดับ
- supply-chain evidence ถูก verify ที่ production admission
- open risk มี owner, expiry และ decision authority
- launch/rollback/incident/recovery plans ถูก exercise
- เนื้อหาและ evidence ตรงกับ release/environment จริง
สรุปคอร์ส
Security Engineering เริ่มจาก asset, threat, trust boundary และ risk แล้วเปลี่ยนเป็น defense-in-depth ที่ enforce และตรวจสอบได้ Identity ปกป้อง actor, authorization ปกป้อง object/action, cryptography ปกป้อง data/channel, network/cloud ลด blast radius, supply chain ปกป้อง artifact และ telemetry/response จำกัดผล เมื่อ control ล้มเหลว Go-live ที่รับผิดชอบจึงเป็น evidence-based risk decision ไม่ใช่ผลจาก checklist เพียงอย่างเดียว