Skip to content

Security — Learning Roadmap

This is the starting point for the enterprise security curriculum. It connects concise concept articles, the evolving reference enterprise system, interactive learning sessions, and evidence gates into one path.

For each unit:

  1. Learn the underlying concepts in the linked security articles.
  2. Apply them to the same enterprise system in the linked curriculum sequence.
  3. Demonstrate the skill through the learning session and required artifact.
  4. Revisit weak areas using the adaptive learning system.

Do not advance because an article was read. Advance when the evidence gate can be completed without relying on an answer key.

Unit 1 — Security Thinking and Trust

Build the mental model used throughout the course: assets, threats, trust boundaries, attack paths, controls, evidence, and residual risk.

Order Learn Apply and demonstrate
1 Security Fundamentals Phase 1: Security Mental Model
2 Core Concepts and Key Principles Learning Session 1: build an asset-to-recovery risk chain
3 Threat-model the reference system Phase 2: Practical Threat Modeling

Exit evidence: risk register, trust-boundary diagram, prioritized threat records, negative tests, and residual-risk owners.

Unit 2 — Identity, Credentials, and Authorization

Follow identity from initial proof through sessions, federation, workload identity, authorization, revocation, and audit.

Order Learn Apply and demonstrate
1 Password Storage and Authentication Mechanisms Compare password, MFA, passkey, certificate, and workload authentication threats
2 Sessions, Tokens & JWT Test expiry, replay, audience, storage, refresh, and revocation behavior
3 OAuth 2.0 and OIDC and Enterprise SSO Trace browser, partner, workforce, and machine identity flows
4 Authorization Models Phase 3: Identity and Access

Exit evidence: identity-flow diagram, principal-to-resource matrix, least-privilege design, lifecycle tests, and privilege-change audit event.

Unit 3 — API, Application, and Data Protection

Turn identity and threat decisions into secure request handling, business invariants, and data-lifecycle controls.

Order Learn Apply and demonstrate
1 API Security Phase 4: API Security
2 Web Attacks & OWASP Top 10 Phase 5: Application Security Patterns
3 Spring Boot API Security Flow Trace source, validation, authorization, sink, response, and telemetry
4 Data classification and lifecycle decisions Phase 6: Data Security

Exit evidence: API inventory, deny-path regression pack, secure code-review trace, data-flow classification, access matrix, and export detection.

Unit 4 — Transport, Network, Cloud, and Runtime

Constrain reachability and blast radius across TLS, GCP, Kubernetes, networks, secrets, and cryptographic operations.

Order Learn Apply and demonstrate
1 Cryptography Basics and HTTPS and TLS Explain the property each primitive provides and validate TLS identity
2 Network Protection Design ingress, egress, segmentation, DDoS, WAF, and zero-trust controls
3 Secrets Management Replace static credentials where possible and exercise rotation and revocation
4 GCP, GKE, network, and cryptographic controls Applied Platform Sessions

Exit evidence: cloud identity map, compromised-pod attack graph, connectivity matrix, TLS validation, secret inventory, and rotation drill.

Unit 5 — Secure Delivery and Security Operations

Carry trust from source to runtime, then detect, investigate, prioritize, recover, and produce governance evidence.

Order Learn Apply and demonstrate
1 Supply-chain and CI/CD trust Software Supply Chain and Secure Delivery
2 Incident response and observability Security Operations, Phases 13–14
3 Vulnerability management and governance Security Operations, Phases 15–16
4 Production hardening Production Security and Operational Readiness

Exit evidence: commit-to-runtime trust map, gate policy, tested detection, incident timeline, risk-ranked backlog, control mapping, and time-bound exception.

Unit 6 — Architecture, AI, and FDE Leadership

Synthesize the preceding units into defensible architecture and customer decisions under ambiguity, delivery pressure, and operational constraints.

Order Learn Apply and demonstrate
1 Architecture patterns and policy as code Advanced Security Patterns
2 Enterprise architecture method Phase 17
3 AI, RAG, and agent security Phase 18
4 Customer leadership and capstone FDE Customer Leadership

Exit evidence: architecture decision record, complete threat model, control/evidence matrix, AI tool-authorization design, incident path, residual-risk decision, and customer recommendation.

  • Complete Units 1–2 in order; every later unit depends on their threat and identity models.
  • Complete Units 3–4 before designing delivery gates or operational detections.
  • Complete Unit 5 before the architecture capstone so designs include evidence and recovery, not only preventive controls.
  • Use the capability map to identify domain gaps and the quick reference during exercises.
  • Return to this roadmap after each evidence gate and record the next gap rather than marking a topic permanently complete.

Core Security Concepts

Vulnerability and Testing Terms

Identity and Access

Cloud and Platform Security

Operations and Governance