Security — Learning Roadmap
1 minute read
A sequential learning path for system design security, from first principles to
enterprise-grade advanced topics. Articles are grouped into phases — each phase
builds on the previous one.
Phase 1 — Foundations
| # |
Article |
You will learn |
| 1 |
Security Fundamentals |
CIA triad, authentication vs authorization vs audit, threat modeling, defense in depth |
| 2 |
Cryptography Basics |
Symmetric vs asymmetric encryption, hashing, MAC/HMAC, digital signatures, PKI |
Phase 2 — Transport Security
| # |
Article |
You will learn |
| 3 |
HTTPS |
TCP + TLS handshake, TLS 1.2 vs 1.3, certificate chain of trust, mTLS |
Phase 3 — Identity & Credentials
Phase 4 — Tokens & Sessions
| # |
Article |
You will learn |
| 6 |
Sessions, Tokens & JWT |
Cookies vs tokens, stateful vs stateless auth, JWT anatomy, refresh tokens, revocation |
Phase 5 — Federated Identity
| # |
Article |
You will learn |
| 7 |
OAuth 2.0 |
Grant types, auth code flow + PKCE, OIDC, scopes and claims |
| 8 |
SSO |
SAML, Active Directory, enterprise federation, Identity-Aware Proxy |
Phase 6 — Authorization
| # |
Article |
You will learn |
| 9 |
Authorization Models |
ACL, RBAC, ABAC, ReBAC, policy engines, least privilege |
Phase 7 — API Security
| # |
Article |
You will learn |
| 10 |
API Security |
HTTPS, OAuth, API keys, rate limiting, gateways, input validation, OWASP API Top 10 |
Phase 8 — Application & Network Protection
Phase 9 — Advanced / Operations
| # |
Article |
You will learn |
| 13 |
Secrets Management |
KMS/HSM, Vault, CyberArk, key rotation, envelope encryption |
Reading tips
- Phases 1–4 are prerequisites for everything after them — don’t skip ahead.
- Phase 5 (OAuth/SSO) is the most interview-heavy section; read it with the
JWT article fresh in mind.
- Phases 6–9 can be read in any order once 1–5 are done.