บทที่ 27 · Part 6 — Advanced Security Engineering

Fintech Security Architecture & Go-Live Checklist

Capstone architecture สำหรับ identity, transaction, data, AWS, supply chain, detection และ evidence-based security go-live decision

ระบบ Fintech เชื่อม identity, money movement, personal data, partner และ cloud control plane เข้าด้วยกัน ความผิดพลาดเพียงจุดเดียวอาจกลายเป็น account takeover, double spend, data breach หรือ outage บทสุดท้ายจึง รวม control จากทุกบทเป็น reference architecture และหลักฐานที่ใช้ตัดสินใจ go-live

Learning Outcomes

  • สร้าง security architecture จาก asset, trust boundary และ transaction invariant ได้
  • เชื่อม identity, web/API/mobile, network, AWS, data และ software supply chain controls ได้
  • แปลง requirement เป็น test/evidence/owner ไม่หยุดที่คำว่า “รองรับ” ได้
  • จัด risk-based go-live review และบันทึก residual-risk decision ได้
  • วาง launch-day monitoring, rollback, incident communication และ post-launch review ได้

Scope and Assumptions

reference platform ในบทนี้มีองค์ประกอบทั่วไป:

  • mobile application และ web application
  • identity/authentication service
  • public API/BFF และ internal services
  • transaction orchestration กับ ledger
  • KYC/document storage
  • partner integration เช่น bank/payment network
  • operations/admin portal
  • AWS multi-account environment
  • CI/CD, artifact registry และ observability/security systems

architecture นี้เป็น learning model ไม่ใช่แบบที่ใช้ได้กับทุก regulatory scope ต้องปรับตาม product, country, payment rail, data residency, availability objective และ risk appetite

Security Objectives

กำหนด objective ก่อนเลือก control:

  1. Account integrity: ผู้โจมตีไม่ยึด account ผ่าน auth/recovery/session path ได้ง่าย
  2. Transaction integrity: amount, currency, source, destination และ approval ไม่ถูกเปลี่ยนหรือ execute ซ้ำ
  3. Ledger integrity: balance invariant ถูก enforce แม้มี retry, race และ partial failure
  4. Data confidentiality: sensitive data ถูกใช้ตาม purpose และเปิดให้ principal ที่จำเป็น
  5. Service availability: critical flow ทน traffic surge, dependency failure และ DDoS ตาม objective
  6. Operational accountability: privileged/business decision trace กลับ actor และ evidence ได้
  7. Recoverability: restore service/data/key/dependency ได้ภายใน tested RTO/RPO

objective ต้องมี measurable acceptance criteria ไม่ใช่คำว่า “ปลอดภัยสูง”

Reference Architecture

diagram ไม่ได้แสดงทุก availability component แต่ทำให้เห็นว่ามีหลาย trust boundaries:

  • untrusted client ถึง public edge
  • edge ถึง application origin
  • public/API tier ถึง identity/transaction/data services
  • transaction domain ถึง external partner
  • operations user ถึง privileged plane
  • workload accounts ถึง security/log archive accounts
  • CI/CD ถึง production deployment

แต่ละ boundary ต้องระบุ protocol, identity, authorization, data, rate/cost limit, timeout/retry, telemetry และ owner

Asset and Data Inventory

AssetSecurity concernExample controls
Identity credential/sessionaccount takeover, replaypasskey/MFA, session rotation/revoke, risk telemetry
Transaction instructiontampering, replay, racedata binding, idempotency, authorization, invariant
Ledger entriesintegrity, privileged mutationappend-oriented model, balanced entries, separation, audit
KYC documentsconfidentiality, retentionisolated store, object authorization, encryption, lifecycle
Partner credential/keyimpersonation, fraudsecret/KMS lifecycle, message signing, rotation
Signing/deploy identitysupply-chain compromiseshort-lived identity, provenance, policy verification
Security logsdeletion, sensitive leakageseparate account, retention, least privilege, integrity
Recovery materialtakeover, lockoutdual control, offline/out-of-band process, exercise

inventory ต้องรวม copy ใน cache, backup, analytics, data lake, support tool และ third party ไม่ใช่เฉพาะ primary database

Trust Boundary Worksheet

สำหรับทุก data flow ให้ตอบ:

  • source principal/workload คือใคร และ identity มาจากไหน
  • destination resource/action คืออะไร
  • ใครควบคุม network/client/runtime
  • input ถูก parse/normalize ที่กี่ hop
  • authorization ตรวจ subject-object-action-context ที่จุดใด
  • message ถูก replay/reordered/delayed/duplicated ได้หรือไม่
  • sensitive field ถูก log/cache/export ที่ใด
  • failure/retry ทำให้ side effect ซ้ำหรือ state ค้างหรือไม่
  • evidence ใดพิสูจน์ว่า control ทำงาน

worksheet ที่ตอบไม่ได้บ่งชี้ architecture gap ไม่ใช่เพียง documentation gap

Identity Architecture

Customer Identity

  • password policy ตาม current guidance และ breached-password screening เมื่อใช้ password
  • phishing-resistant option เช่น passkey
  • step-up ตาม action/risk ไม่ใช่ sign-in อย่างเดียว
  • anti-enumeration และ rate/abuse controls
  • authenticator enrollment/replacement notification
  • recovery ที่ไม่อ่อนกว่า primary authentication
  • session/device inventory และ revoke path
  • support override ผ่าน verified, audited workflow

รายละเอียดอยู่ใน Identity & Authentication, Strong Authentication & Account Recovery และ Session & Token Security

Workforce and Privileged Identity

  • federation/central lifecycle ไม่มี shared admin identity
  • phishing-resistant MFA สำหรับ privileged access
  • role/permission ตาม duty และ environment
  • just-in-time/time-bound elevation
  • maker-checker สำหรับ high-impact action
  • independent break-glass พร้อม alert/post-use review
  • administrative action log ที่ operator แก้ไม่ได้

privileged portal ควรแยก origin/API/path จาก customer channel และไม่มี direct database mutation

Workload Identity

  • dedicated role ต่อ service/environment
  • temporary credential ไม่มี embedded long-lived key
  • audience/action/resource scope
  • constrained cross-account trust
  • secret only เมื่อ target ไม่รองรับ workload federation
  • rotation/revoke และ identity telemetry

AWS details อยู่ใน AWS IAM & Workload Identity

Authorization Model

authorization ต้อง enforce ที่ server ทุก object/action:

  • customer อ่าน/แก้เฉพาะ resource ที่ relationship อนุญาต
  • support role เห็น field เท่าที่ task ต้องใช้
  • operator action มี reason/ticket/approval ตาม sensitivity
  • service role เรียกเฉพาะ downstream action ที่จำเป็น
  • tenant boundary อยู่ใน query/storage invariant ไม่พึ่ง UI filter
  • export/bulk/search มี scope, purpose และ rate limit

ใช้ RBAC สำหรับ job function, ABAC สำหรับ context/attribute และ ReBAC สำหรับ relationship ตาม domain แต่ attribute/relationship source ต้องถูกป้องกัน รายละเอียดอยู่ใน Authorization & Access Control

Transaction Integrity

transaction request ควรมี canonical business intent:

  • operation ID
  • source account/wallet
  • destination/beneficiary identity
  • amount เป็น integer หน่วยสตางค์
  • currency
  • fee/exchange information
  • purpose/reference เมื่อจำเป็น
  • approval/risk context
  • expiry/freshness

ผู้ใช้หรือ approver ต้องเห็นข้อมูลสำคัญที่ระบบจะ execute และการเปลี่ยน field ใดต้อง invalidate approval

Idempotency and Replay

  • bind idempotency key กับ caller, operation และ canonical request hash
  • create key/result/state transition แบบ atomic
  • same key + different payload ต้อง reject
  • webhook/message ตรวจ signature, timestamp, key ID และ replay uniqueness
  • retention window ครอบคลุม real retry behavior
  • idempotency ไม่แทน authentication หรือ nonce/freshness

Ledger Invariants

  • double-entry/balanced-entry invariant ตาม ledger model
  • unique business operation/reference
  • atomic posting หรือ explicit pending/commit/reverse state machine
  • immutable audit of correction/reversal แทนแก้ประวัติแบบเงียบ
  • concurrency control ที่ database/durable boundary
  • reconciliation กับ partner/source of truth

รายละเอียดอยู่ใน API Abuse & Transaction Integrity

Risk and Fraud Policy ต้องมี Human Owner

threshold, hold, manual review, beneficiary cooling period และ degraded-mode decision กระทบลูกค้าและธุรกิจ ต้องมี Product/Operations/Risk/Compliance authority ตาม scope ไม่ควรฝังเป็น technical default ที่ไม่มี owner

API Security

public/internal API ต้องมี:

  • explicit schema และ reject unknown/ambiguous input ตาม contract
  • authentication แยกจาก object/function/property authorization
  • request/body/decompression/response/query complexity limits
  • per-principal/object/tenant/global/concurrency/cost limits
  • safe error และ no stack/secret leakage
  • inventory/version/deprecation owner
  • third-party API trust/timeout/retry/circuit behavior
  • security event/correlation ID

OAuth/OIDC flow ต้องใช้ profile ที่เหมาะกับ client, PKCE/redirect/state/nonce validation และ audience/scopes ที่แคบ OAuth 2.1 ยังไม่ควรถูกอ้างว่าเป็น RFC final รายละเอียดอยู่ใน API Security Foundations และ OAuth, OIDC & Service Authentication

Web Security

web architecture ต้องพิจารณา:

  • BFF/server session สำหรับ sensitive browser application เมื่อเหมาะสม
  • Secure, HttpOnly, SameSite cookie และ CSRF defense
  • output encoding ตาม context และ safe templating
  • CSP/Trusted Types เป็น defense-in-depth ต่อ XSS
  • clickjacking/frame policy
  • CORS allowlist ตาม origin/method/header/credential semantics
  • no sensitive token ใน browser storage เมื่อหลีกเลี่ยงได้
  • secure upload/scanning/quarantine/download pipeline สำหรับเอกสาร
  • cache control ป้องกันข้อมูลข้าม user/tenant

ดู Web Security Model, Injection & Input Security และ Browser & Content Security

Mobile Security

mobile client อยู่ใน attacker-controlled environment จึงไม่เก็บ server secret หรือ trust authorization decision ที่มีเฉพาะ client

  • platform-backed Keystore/Keychain สำหรับ key/token ตาม risk
  • biometric ผูก cryptographic operation เมื่อใช้ยืนยัน local key
  • external user-agent + PKCE สำหรับ OAuth
  • validate universal/app/deep links
  • WebView bridge/navigation จำกัดอย่างเข้ม
  • minimize backup, log, clipboard, screenshot, notification และ analytics leakage
  • attestation/root detection/obfuscation เป็น risk signals ไม่ใช่ trust anchor
  • pinning มี rotation/recovery strategy หาก threat model เลือกใช้
  • secure signed update/no downgrade ตาม risk

verification ใช้ MASVS/MASTG ร่วมกับ backend/API standard ตาม Mobile Security Foundations และ Mobile Hardening & Testing

Data Protection

Customer and KYC Data

  • classify fields/documents และ purpose
  • object/tenant authorization ทุก read/write/export
  • isolate KYC store/service path
  • encrypt at rest/in transit พร้อม key policy
  • malware/content pipeline สำหรับ upload
  • no public bucket/origin
  • pre-signed URL มี short expiry, scope และ signer permission
  • retention/deletion/legal hold workflow
  • backup restore พร้อม key dependency test

Logging and Analytics

  • minimize/redact/tokenize sensitive fields
  • no password, full token, secret หรือ raw payment data
  • access/query/export audit
  • retention by purpose
  • production-to-analytics pipeline มี schema/field approval
  • test deletion/subject workflow ครอบคลุม derived copy ตาม applicable policy

AWS controls อยู่ใน AWS Data & Workload Protection

Cryptographic Architecture

  • TLS พร้อม hostname/service identity validation ทุก trust boundary
  • approved maintained algorithms/libraries
  • separate encryption, MAC และ signature objectives
  • KMS/HSM ตาม key assurance/throughput/integration need
  • envelope encryption และ encryption context ที่ไม่มี PII/secret
  • key owner, cryptoperiod, rotate/revoke/disable/delete authority
  • partner/message signature canonicalization และ replay state
  • crypto-agility inventory สำหรับ algorithm/key migration

การเปิด KMS rotation ไม่ re-encrypt ข้อมูลเดิมและไม่ revoke compromised old material ดูรายละเอียดใน Cryptography, Keys & Secrets

AWS Organization Design

ขั้นต่ำที่ควรพิจารณา:

  • management account ไม่มี workload/routine admin
  • dedicated Log Archive และ Security Tooling accounts
  • production/non-production/sandbox แยกตาม control profile
  • workload/data boundary แยก account เพิ่มตาม sensitivity
  • Organizations/OU/SCP guardrails แบบ staged
  • account vending และ baseline-as-code
  • root protection/recovery และ break-glass
  • centralized service delegation

SCP เป็น maximum-permission guardrail ไม่ grant permission และไม่จำกัด management account ดู AWS Security Foundations & Multi-Account Design

Network Architecture

  • trusted edge path: DNS → CDN/WAF/API Gateway/ALB → origin
  • origin ไม่เปิด bypass path เมื่อ architecture รองรับ
  • private application/data subnets ตาม effective routes
  • SG แยก edge-to-api, api-to-service, service-to-data
  • VPC endpoint พร้อม scoped endpoint/resource/IAM policies
  • controlled egress สำหรับ partner/update/telemetry
  • no public administrative port; audited session path
  • Flow Logs/DNS/WAF/load balancer/firewall/application evidence
  • DDoS load shedding และ critical-flow prioritization

private subnet/NAT/PrivateLink ไม่แทน authorization ดู AWS Network & Edge Security และ Network Defense, Detection & Zero Trust

Partner Integration

partner boundary ต้องกำหนด:

  • network endpoint และ TLS service identity
  • client/workload authentication
  • message/request signature coverage
  • clock/timestamp/nonce/replay window
  • canonical request/response schema
  • idempotency/reconciliation identifier
  • timeout/retry/backoff/circuit breaker
  • rate/quota และ partner outage behavior
  • credential/key rotation overlap
  • callback/webhook verification
  • dispute/reconciliation/evidence process

IP allowlist เป็น defense-in-depth ไม่ใช่ partner identity เพียงอย่างเดียว

Software Delivery

Source and CI

  • protected branch/tag, review และ security-sensitive CODEOWNERS
  • phishing-resistant maintainer/admin access
  • isolated untrusted pull-request builds
  • pinned CI action/plugin/image
  • short-lived scoped OIDC identity
  • secret masking และ no production secret in build
  • IaC/policy/code/dependency tests

Artifact and Deploy

  • build once in ephemeral isolated builder
  • SBOM และ provenance
  • vulnerability/malware/license signals ตาม policy
  • sign artifact
  • verify digest, signer/issuer/claims/provenance ที่ admission
  • promote immutable digest ไม่ rebuild/tag drift
  • time-bound exception พร้อม owner
  • rollback ใช้ known-good signed artifact

ดู Secure Development Lifecycle และ Advanced Attacks & Software Supply Chain

Detection Architecture

Cloud Signals

  • organization CloudTrail trail + selected data events
  • Config state/rules
  • GuardDuty every intended Region/protection plan
  • Macie targeted/automated discovery ตาม data scope
  • Security Hub/Security Hub CSPM aggregation/correlation
  • VPC Flow Logs, DNS, WAF และ workload/runtime telemetry

Business Security Signals

  • auth/recovery/authenticator/session changes
  • beneficiary/instruction/approval changes
  • replay/idempotency/rate/concurrency denials
  • unusual data search/export
  • privileged override
  • ledger correction/reversal/reconciliation mismatch
  • partner signature/freshness failures

cloud finding ต้อง correlate กับ application actor/object/transaction context โดยไม่ log sensitive payload เกินจำเป็น ดู AWS Logging, Detection & Incident Response

Incident Response Architecture

เตรียม runbook อย่างน้อย:

  • customer account takeover
  • workforce/privileged identity compromise
  • workload role/secret compromise
  • public data exposure/exfiltration
  • ledger/transaction integrity incident
  • malicious deployment/supply-chain compromise
  • DDoS/dependency/partner outage
  • logging/detection failure
  • KMS key disable/delete/compromise
  • ransomware/operator deletion และ restore

แต่ละ runbook ระบุ evidence, authority, reversible containment, customer/business impact, communication และ recovery validation

Security Requirements Matrix

ทุก requirement ควรมีรูปแบบ:

Fieldความหมาย
IDstable requirement identifier
Asset/threatสิ่งที่ป้องกันและเหตุโจมตี
Requirementbehavior ที่ต้องเกิด/ห้ามเกิด
Control ownerผู้สร้าง/ดูแล control
Testวิธี positive/negative/adversarial verification
Evidenceresult/config/log/report ที่ review ได้
Runtime signalวิธีตรวจ drift/failure/attack
Exceptionreason, compensating control, owner, expiry

ตัวอย่าง requirement ที่ตรวจได้:

SEC-TX-007
Threat: duplicate or concurrent debit violates balance invariant
Requirement: one operation ID posts at most once and balance never crosses allowed boundary
Test: concurrent integration test with retries and storage-level failure injection
Evidence: test result, database constraint/state-machine definition, deployment revision
Runtime signal: duplicate-key conflict rate, invariant monitor, reconciliation mismatch

คำว่า “ใช้ WAF”, “เข้ารหัส” หรือ “มี MFA” เป็น control statement ที่ยังไม่บอก objective, scope และ evidence

Verification Strategy

LayerVerification
Requirement/designthreat model, abuse cases, architecture review
Codepeer review, SAST, secret scan, unit/property tests
Dependency/artifactSCA, SBOM, image scan, signature/provenance verification
API/webASVS-based tests, DAST, authz/negative/abuse tests
MobileMASVS requirements + MASTG static/dynamic tests
InfrastructureIaC tests, policy analysis, config drift, attack-path review
Runtimedetection simulation, load/failure/security game day
Recoverybackup/key/restore and incident tabletop

automated scan ไม่แทน manual architecture/business-logic review และ penetration test ไม่แทน continuous controls

Performance and Security

security limit ต้องทดสอบกับ capacity:

  • login/OTP/step-up vendor quota
  • API per-user/global/cost/concurrency limits
  • KMS/Secrets Manager/service quotas
  • database connection/lock contention
  • queue lag และ retry storm
  • WAF/edge/origin capacity
  • partner timeout/rate/outage
  • security log volume/query/delivery

failure mode ต้องไม่เปิด permission กว้าง, skip signature/authorization หรือ execute transaction ซ้ำ

Go-Live Gates

Gate 1 — Scope and Ownership

  • architecture/data-flow diagrams เป็น revision ปัจจุบัน
  • assets/data classification/third parties ครบตาม known scope
  • production account/service/Region owners ชัด
  • security requirement และ risk register มี stable IDs
  • legal/compliance/privacy interpretation มี responsible authority

Gate 2 — Identity and Transaction

  • customer/admin/workload identities ใช้ intended production paths
  • recovery, support override และ break-glass tested
  • object/function/property authorization negative tests ผ่าน
  • transaction-data binding/idempotency/replay/race invariants ผ่าน
  • ledger/reconciliation/approval flows มี business owner sign-off

Gate 3 — Data and Cloud

  • public/cross-account/data export paths reviewed
  • KMS/key/secret rotation-recovery dependencies tested
  • backup restore วัด RTO/RPO จริง
  • accounts/SCP/IAM/network/endpoints/egress ตรง baseline
  • production logging/detection enrollment ครบทุก intended Region

Gate 4 — Software and Operations

  • source/CI/artifact/deploy verification enforce ใน production
  • critical/high findings resolved หรือมี approved exception
  • capacity, abuse, DDoS และ dependency failure tested
  • dashboards/alerts/on-call/runbooks พร้อม
  • rollback ใช้ artifact/config/data procedure ที่ทดสอบแล้ว

Gate 5 — Incident and Decision

  • tabletop ครอบคลุม high-impact scenario
  • contacts/authority/out-of-band channel ยืนยันแล้ว
  • open residual risks มี likelihood/impact/compensating control/expiry
  • launch/rollback criteria มีผู้ตัดสิน
  • evidence package ถูก review และเก็บตาม policy

Detailed Go-Live Checklist

Governance and Threat Model

  • product/data/architecture scope และ assumptions เป็นปัจจุบัน
  • asset, actor, dependency และ trust boundary มี owner
  • STRIDE/abuse/business-fraud scenarios ถูกจัดลำดับ
  • control map เชื่อม requirement → test → evidence → runtime signal
  • exception ทุกตัวมี residual-risk owner และ expiry
  • no tool/service ถูกอ้างว่า “ทำให้ผ่าน compliance” โดยไม่มี scope/evidence review

Identity and Access

  • workforce/admin ใช้ federation และ phishing-resistant MFA ตาม risk
  • customer MFA/passkey/recovery/session paths ผ่าน takeover tests
  • dormant/terminated identity lifecycle ทำงาน
  • role/permission/trust/PassRole/cross-account paths reviewed
  • no shared/embedded long-lived production key
  • privileged elevation/maker-checker/break-glass time-bound และ audited
  • Access Analyzer/policy tests ครอบคลุม allow และ deny path

Transaction and Ledger

  • canonical instruction bind amount/currency/source/destination/fee/operation
  • approval invalidated เมื่อ protected transaction data เปลี่ยน
  • idempotency bind caller + operation + request hash แบบ atomic
  • replay state/window และ webhook/message signature tested
  • concurrent/failure/retry tests รักษา ledger invariant
  • duplicate/reversal/refund/dispute flows มี explicit state machine
  • reconciliation mismatch มี alert, owner และ correction policy

Web, API and Mobile

  • schema validation, output encoding และ safe error ครบ boundary
  • XSS/CSRF/CORS/CSP/clickjacking/cache controls verified
  • BOLA/function/property authorization มี negative tests
  • body/query/decompression/rate/cost/concurrency limits tested
  • OAuth/OIDC redirect/PKCE/state/nonce/issuer/audience/type checks ผ่าน
  • mobile storage/link/WebView/backup/log/clipboard/SDK exposure reviewed
  • attestation/root/pinning signals ไม่ถูกใช้เป็น authorization proof เดี่ยว
  • file upload quarantine/scan/download authorization tested

Data, Keys and Secrets

  • sensitive fields/documents มี purpose, location, retention และ deletion owner
  • encryption at rest/in transit ไม่ถูกใช้แทน authorization
  • KMS key policy/grant/context/admin-user separation reviewed
  • key disable/delete/compromise และ restore procedure tested
  • secret rotation ครอบคลุม consumer cache/overlap/revoke/rollback
  • S3 public/access point/policy/pre-signed URL/version/Object Lock paths reviewed
  • database snapshot/export/backup/cross-account paths restricted
  • log/analytics/crash/support tools ไม่มี sensitive data เกิน purpose

AWS and Network

  • management, Log Archive, Security Tooling และ workload accounts แยกตาม design
  • root protection/contact/recovery และ organization account inventory ครบ
  • SCP/landing-zone baseline ผ่าน staged test และ drift reconciliation
  • effective routes, SG, NACL, endpoint, edge และ origin paths reviewed
  • origin/admin/data plane ไม่มี unintended public/bypass route
  • private endpoint policies จำกัด principal/action/resource
  • egress ครอบคลุม route/DNS/firewall/proxy/identity/destination validation
  • Network Firewall path symmetric และ failure mode tested
  • DDoS/load shedding/degraded mode มี business approval

Software Supply Chain

  • maintainer/repository/CI identities protected และ scoped
  • untrusted build แยกจาก release secret/environment
  • dependencies/actions/images pinned และมี update process
  • build ephemeral/isolated และ produce artifact ครั้งเดียว
  • SBOM/provenance/signature/scan ถูกสร้างและเก็บกับ digest
  • deployment verify trusted signer/issuer/claims/provenance/digest
  • production admission/bypass/break-glass audited
  • rollback artifact เป็น known-good immutable digest

Detection and Response

  • organization CloudTrail + required data events ส่ง Log Archive สำเร็จ
  • Config/GuardDuty/Macie/Security Hub coverage ทุก account/Region ที่ตั้งใจ
  • Flow/DNS/WAF/edge/workload/application logs มี retention/access/privacy policy
  • delivery health และ control-disable change alert
  • auth/transaction/data/admin security events มี correlation ID
  • critical detection ทุกตัวมี owner/runbook/test/containment authority
  • evidence store และ integrity/retrieval validation exercised
  • incident access ใช้ได้เมื่อ primary IdP/control path ล่ม
  • containment preserve evidence และ rollback ได้เมื่อเหมาะสม

Reliability and Recovery

  • load/capacity/soak tests รวม security controls
  • dependency timeout/retry/backoff/circuit/quota behavior tested
  • queue/retry storm ไม่ bypass limit หรือ duplicate side effect
  • backup restore รวม key, IAM, network, config และ application dependency
  • measured RTO/RPO ตรง approved objective
  • Region/account/partner outage runbook tested ตาม scope
  • rollback criteria, data migration compatibility และ decision owner ชัด

Evidence Package

ก่อน review ควรรวม link/reference ไม่ copy secret:

  • architecture/data-flow/threat model revision
  • requirements/control/evidence matrix
  • IAM/network/KMS/data-policy review results
  • ASVS/MASVS/API verification records
  • code/dependency/image/IaC/SBOM/provenance results
  • performance/failure/concurrency/security test results
  • detection simulation และ tabletop report
  • backup/restore RTO/RPO evidence
  • open findings/exceptions/risk acceptance
  • launch/rollback/on-call/communication plan

evidence ต้อง reproducible และผูกกับ version/environment ที่จะ deploy รายงานจาก artifact หรือ configuration เก่า ไม่ใช่หลักฐานของ release ปัจจุบัน

Residual Risk Decision

ไม่มี launch ที่ risk เป็นศูนย์ รายการที่ยังเปิดควรบันทึก:

  • risk statement: threat → vulnerability/control gap → impact
  • affected assets/users/flows
  • likelihood/impact และ uncertainty
  • current/compensating controls
  • evidence และ blind spots
  • remediation owner/date
  • exception expiry/review trigger
  • accept/mitigate/avoid/transfer decision
  • accountable authority

Engineer ไม่ควร Accept Business/Compliance Risk แทนผู้มีอำนาจ

หน้าที่ทางเทคนิคคือให้ข้อมูลที่ตรวจสอบได้ อธิบาย scenario/impact/control gap และเสนอทางเลือก การรับ residual risk ที่กระทบเงิน ข้อมูลส่วนบุคคล กฎหมาย หรือ availability ต้องมีผู้รับผิดชอบตาม governance

Launch-Day Plan

Before Launch

  • freeze window/change ownership ตาม risk
  • verify artifact digest/config/migration
  • confirm on-call, war room และ out-of-band contacts
  • check dashboards/log delivery/detection test event
  • verify backup/rollback state
  • confirm partner capacity/status/credential
  • record go/no-go authority และ time

During Launch

  • deploy staged/canary เมื่อ architecture รองรับ
  • monitor auth success/failure, authorization denial, transaction/error/latency
  • monitor idempotency/replay/invariant/reconciliation signals
  • monitor edge/WAF/rate/DDoS/cost/dependency
  • monitor CloudTrail/config/security findings
  • pause/rollback ตาม pre-defined criteria

After Launch

  • verify no security control/telemetry silently degraded
  • reconcile transactions/data migration
  • review new permission/network/data paths
  • close หรือ carry forward findings อย่างมี owner
  • capture incident/near-miss/operational learning
  • schedule 24-hour, 7-day และ 30-day review ตาม risk

Continuous Security after Go-Live

go-live เป็น checkpoint ไม่ใช่ปลายทาง:

  • threat model เมื่อ feature/data/partner/architecture เปลี่ยน
  • patch/dependency/key/secret/certificate lifecycle
  • access/exception/account/resource review
  • periodic authorization/abuse/mobile verification
  • detection regression/purple-team/tabletop
  • backup/restore และ break-glass exercise
  • metric review: coverage, finding age, exception age, detection/containment/recovery time
  • post-incident corrective actions ที่มี owner/due date

Security program ที่ดีลดเวลาระหว่าง drift/attack กับการค้นพบและจำกัดผล ไม่ใช่คาดหวังว่าจะป้องกันทุกเหตุ

Framework Mapping

ใช้ framework หลายตัวตาม scope:

  • NIST CSF 2.0: Govern, Identify, Protect, Detect, Respond, Recover
  • NIST SSDF: secure software development practices
  • OWASP ASVS 5.0: web/application/API verification requirements
  • OWASP API Security Top 10:2023: API risk awareness
  • OWASP MASVS/MASTG: mobile requirements และ test evidence
  • AWS Well-Architected Security Pillar: cloud architecture review lens
  • OWASP Top 10:2025: application risk awareness/communication

framework หนึ่งไม่แทนอีก framework และไม่มีรายการใดรับรอง compliance โดยอัตโนมัติ

Final Review

  • architecture อธิบาย asset, identity, trust boundary, data และ transaction invariant ได้
  • prevention, detection, response และ recovery เชื่อมกัน
  • control สำคัญมี negative/adversarial/failure test
  • cloud และ application telemetry ครอบคลุม scenario ที่จัดลำดับ
  • supply-chain evidence ถูก verify ที่ production admission
  • open risk มี owner, expiry และ decision authority
  • launch/rollback/incident/recovery plans ถูก exercise
  • เนื้อหาและ evidence ตรงกับ release/environment จริง

สรุปคอร์ส

Security Engineering เริ่มจาก asset, threat, trust boundary และ risk แล้วเปลี่ยนเป็น defense-in-depth ที่ enforce และตรวจสอบได้ Identity ปกป้อง actor, authorization ปกป้อง object/action, cryptography ปกป้อง data/channel, network/cloud ลด blast radius, supply chain ปกป้อง artifact และ telemetry/response จำกัดผล เมื่อ control ล้มเหลว Go-live ที่รับผิดชอบจึงเป็น evidence-based risk decision ไม่ใช่ผลจาก checklist เพียงอย่างเดียว

Further Reading