Skip to main content

ENGINEERING GUIDES & CHECKLISTS

Security Engineering Resources

Actionable checklists and preparation guides developed by our offensive security team to help engineering organizations strengthen defensive postures and prepare for security testing.

Practical GuideRajSecure Guide

Preparing for a Penetration Test: Engineering Checklist

A comprehensive checklist to help engineering, DevOps, and product teams prepare staging environments, test accounts, API specifications, and IP whitelists for a seamless penetration test.

Key Checklist Points:

  • Provision at least 2 test accounts per role tier for authorization testing
  • Provide current OpenAPI / Swagger or Postman collection specifications
  • Whitelist tester source IP addresses in WAF / rate-limiting appliances if agreed in RoE
  • Establish primary and secondary emergency contact escalation trees
  • Verify that database backups and snapshot mechanisms are current in staging
Security ChecklistRajSecure Guide

API Security Architecture Checklist (OWASP API Top 10 Aligned)

Essential security controls to implement across REST, GraphQL, and microservice APIs to prevent broken object-level authorization, mass assignment, and token leakage.

Key Checklist Points:

  • Enforce server-side tenant and user ID authorization checks on every object lookup (BOLA)
  • Validate that all administrative and mutating actions require explicit permission claims (BFLA)
  • Implement strict schema validation to block mass assignment and object injection
  • Apply rate-limiting and resource-quota caps per API key and authenticated user ID
  • Ensure tokens (JWT) use asymmetric keys (RS256/EdDSA) and validate audience/expiry strictly
Procurement ChecklistRajSecure Guide

B2B SaaS Security & Procurement Readiness Checklist

The foundational security controls and policies required to pass enterprise buyer vendor security reviews and satisfy SOC 2 / ISO 27001 audit mandates.

Key Checklist Points:

  • Maintain annual third-party penetration testing reports with Letters of Attestation
  • Enforce multi-factor authentication (MFA) and SSO support (SAML/OIDC) for enterprise tiers
  • Implement strict multi-tenant database partitioning and cross-tenant automated tests
  • Publish a formal Responsible Disclosure / Vulnerability Reporting policy
  • Maintain continuous encryption at rest (AES-256) and in transit (TLS 1.3)
Infrastructure GuideRajSecure Guide

AWS & Multi-Cloud Infrastructure Hardening Checklist

Key architectural controls to eliminate over-privileged IAM roles, public bucket exposures, and unsegmented network access across cloud environments.

Key Checklist Points:

  • Enforce IMDSv2 with hop-limit 1 on all compute instances to prevent SSRF credential theft
  • Audit and eliminate wildcard permissions (`*:*`) in IAM role policies
  • Enable AWS CloudTrail / GCP Audit Logs with multi-region integrity validation and alerting
  • Block all public S3 bucket access at the organizational level and enforce KMS encryption
  • Migrate Kubernetes pods from node instance profiles to least-privilege IAM service roles
Remediation GuideRajSecure Guide

Vulnerability Remediation & Triage Guide

A structured workflow for engineering teams to prioritize, remediate, and request verification retests following an offensive security assessment.

Key Checklist Points:

  • Triage vulnerabilities by business risk and exploitability, not generic CVSS scores alone
  • Establish fixed remediation SLAs (Critical: 7 days, High: 14 days, Medium: 30 days)
  • Address root cause architectural patterns rather than applying fragile parameter regexes
  • Write automated regression unit/integration tests for each verified vulnerability PoC
  • Request formal remediation retesting from RajSecure to receive updated Attestation Letters

Need a Guided Security Assessment for Your Team?

We partner with your developers to conduct authorized testing, provide engineer-ready remediation, and verify fixes.