DSE security knowledge hub

Security knowledge,
without the noise.

Page 11 of the DSE Security Knowledge Hub, with source-backed guidance, checklists, explainers, and playbooks.

DSE-authoredOfficial sourcesReviewed guidance
DSE post stream

Guidance and analysis from DSE

254 articles
DSE visual briefContinuity & recovery

Treat Terraform state as production data with locking and recovery

Terraform state binds configuration to real infrastructure and can contain sensitive data. A team needs controlled remote storage, supported locking, restricted access, serialized changes, versioned recovery, and a tested process for failed writes.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the checklist
DSE visual briefNetworks & infrastructure

Design Azure Private Endpoint DNS before the first private link

An approved Azure Private Endpoint can still fail when clients resolve the public address or a private zone returns NXDOMAIN. Design service-specific zones, VNet links, hybrid forwarding, fallback, ownership, and tests before deployment.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the guide
DSE visual briefNetworks & infrastructure

Test Path MTU across tunnels and cloud edges before applications stall

VPN, overlay, encapsulation, and cloud paths can carry less payload than an endpoint interface suggests. Validate bidirectional Path MTU, ICMP behavior, transport adaptation, and representative applications before intermittent stalls reach production.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the playbook
DSE visual briefContinuity & recovery

Treat the domain registrar as a business-critical control plane

Control of a domain registration can redirect websites and email, disrupt public services, or remove an organization’s online identity. Registrar access deserves named ownership, strong authentication, locks, monitored changes, and an exercised recovery plan.

Published Reviewed 4 min readBy Gavin Stewart
Read the checklist