Security — Learning Roadmap
This is the starting point for the enterprise security curriculum. It connects concise concept articles, the evolving reference enterprise system, interactive learning sessions, and evidence gates into one path.
For each unit:
- Learn the underlying concepts in the linked security articles.
- Apply them to the same enterprise system in the linked curriculum sequence.
- Demonstrate the skill through the learning session and required artifact.
- Revisit weak areas using the adaptive learning system.
Do not advance because an article was read. Advance when the evidence gate can be completed without relying on an answer key.
Unit 1 — Security Thinking and Trust
Build the mental model used throughout the course: assets, threats, trust boundaries, attack paths, controls, evidence, and residual risk.
| Order | Learn | Apply and demonstrate |
|---|---|---|
| 1 | Security Fundamentals | Phase 1: Security Mental Model |
| 2 | Core Concepts and Key Principles | Learning Session 1: build an asset-to-recovery risk chain |
| 3 | Threat-model the reference system | Phase 2: Practical Threat Modeling |
Exit evidence: risk register, trust-boundary diagram, prioritized threat records, negative tests, and residual-risk owners.
Unit 2 — Identity, Credentials, and Authorization
Follow identity from initial proof through sessions, federation, workload identity, authorization, revocation, and audit.
| Order | Learn | Apply and demonstrate |
|---|---|---|
| 1 | Password Storage and Authentication Mechanisms | Compare password, MFA, passkey, certificate, and workload authentication threats |
| 2 | Sessions, Tokens & JWT | Test expiry, replay, audience, storage, refresh, and revocation behavior |
| 3 | OAuth 2.0 and OIDC and Enterprise SSO | Trace browser, partner, workforce, and machine identity flows |
| 4 | Authorization Models | Phase 3: Identity and Access |
Exit evidence: identity-flow diagram, principal-to-resource matrix, least-privilege design, lifecycle tests, and privilege-change audit event.
Unit 3 — API, Application, and Data Protection
Turn identity and threat decisions into secure request handling, business invariants, and data-lifecycle controls.
| Order | Learn | Apply and demonstrate |
|---|---|---|
| 1 | API Security | Phase 4: API Security |
| 2 | Web Attacks & OWASP Top 10 | Phase 5: Application Security Patterns |
| 3 | Spring Boot API Security Flow | Trace source, validation, authorization, sink, response, and telemetry |
| 4 | Data classification and lifecycle decisions | Phase 6: Data Security |
Exit evidence: API inventory, deny-path regression pack, secure code-review trace, data-flow classification, access matrix, and export detection.
Unit 4 — Transport, Network, Cloud, and Runtime
Constrain reachability and blast radius across TLS, GCP, Kubernetes, networks, secrets, and cryptographic operations.
| Order | Learn | Apply and demonstrate |
|---|---|---|
| 1 | Cryptography Basics and HTTPS and TLS | Explain the property each primitive provides and validate TLS identity |
| 2 | Network Protection | Design ingress, egress, segmentation, DDoS, WAF, and zero-trust controls |
| 3 | Secrets Management | Replace static credentials where possible and exercise rotation and revocation |
| 4 | GCP, GKE, network, and cryptographic controls | Applied Platform Sessions |
Exit evidence: cloud identity map, compromised-pod attack graph, connectivity matrix, TLS validation, secret inventory, and rotation drill.
Unit 5 — Secure Delivery and Security Operations
Carry trust from source to runtime, then detect, investigate, prioritize, recover, and produce governance evidence.
| Order | Learn | Apply and demonstrate |
|---|---|---|
| 1 | Supply-chain and CI/CD trust | Software Supply Chain and Secure Delivery |
| 2 | Incident response and observability | Security Operations, Phases 13–14 |
| 3 | Vulnerability management and governance | Security Operations, Phases 15–16 |
| 4 | Production hardening | Production Security and Operational Readiness |
Exit evidence: commit-to-runtime trust map, gate policy, tested detection, incident timeline, risk-ranked backlog, control mapping, and time-bound exception.
Unit 6 — Architecture, AI, and FDE Leadership
Synthesize the preceding units into defensible architecture and customer decisions under ambiguity, delivery pressure, and operational constraints.
| Order | Learn | Apply and demonstrate |
|---|---|---|
| 1 | Architecture patterns and policy as code | Advanced Security Patterns |
| 2 | Enterprise architecture method | Phase 17 |
| 3 | AI, RAG, and agent security | Phase 18 |
| 4 | Customer leadership and capstone | FDE Customer Leadership |
Exit evidence: architecture decision record, complete threat model, control/evidence matrix, AI tool-authorization design, incident path, residual-risk decision, and customer recommendation.
Recommended progression
- Complete Units 1–2 in order; every later unit depends on their threat and identity models.
- Complete Units 3–4 before designing delivery gates or operational detections.
- Complete Unit 5 before the architecture capstone so designs include evidence and recovery, not only preventive controls.
- Use the capability map to identify domain gaps and the quick reference during exercises.
- Return to this roadmap after each evidence gate and record the next gap rather than marking a topic permanently complete.