Role Guides
Security Partner Guide
Security partners use the blue book to turn security requirements into practical controls, evidence, and guardrails that engineering teams can adopt.
Read first
Start with:
- Security and Governance
- Threat Modeling
- Supply Chain Security
- Identity and Access
- Compliance Evidence
Security partner responsibilities
Security partners should:
- Define required controls and risk thresholds.
- Help teams threat model high-risk changes.
- Review exceptions and compensating controls.
- Ensure evidence comes from systems of record.
- Partner on incident response and vulnerability management.
- Make guardrails automatable where possible.
Review questions
Ask:
- What data is in scope?
- Where does trust change?
- Which identities can affect production?
- How are artifacts built, verified, and deployed?
- What evidence proves the control works?
- What exceptions exist and when do they expire?
Watchouts
- Policy without enablement creates bypass behavior.
- Manual evidence collection does not scale.
- Security exceptions need owners and expiry dates.
- AI and automation tools need data and permission boundaries.