DSE security knowledge hub

Security knowledge,
without the noise.

Page 16 of the DSE Security Knowledge Hub, with source-backed guidance, checklists, explainers, and playbooks.

DSE-authoredOfficial sourcesReviewed guidance
DSE post stream

Guidance and analysis from DSE

254 articles
DSE visual briefNetworks & infrastructure

Run TLS certificates as an enterprise service, not a renewal calendar

NIST NCCoE treats TLS server certificates as an enterprise operating program: policy, discovery, ownership, controlled issuance, key protection, automation, monitoring, emergency replacement, and auditable evidence.

Published Reviewed 4 min readBy DSE Security Editorial Team
Read the guide
DSE visual briefIdentity & cloud

Give every non-human Microsoft Entra identity an owner and an end date

Managed identities, service principals, and user-based service accounts can retain access without human visibility. Choose the safest type, record ownership and purpose, control permissions and credentials, monitor use, and retire dependencies safely.

Published Reviewed 4 min readBy DSE Security Editorial Team
Read the guide
DSE visual briefManaged IT operations

Build an evidence-based exit from Windows Server 2016 before January 12, 2027

Windows Server 2016 extended support ends January 12, 2027. An exit plan needs workload ownership, dependency and compatibility evidence, a supported target path, tested recovery, migration proof, and documented retirement—not only an OS count.

Published Reviewed 3 min readBy DSE Security Editorial Team
Read the playbook
DSE visual briefIdentity & cloud

Turn FFIEC authentication guidance into a layered-control evidence plan

FFIEC's authentication and access guidance is risk-based, not an MFA-only checklist. Covered institutions can translate it into scoped risk decisions, layered preventive, detective, and corrective controls, testing, residual-risk approval, and examination-ready evidence.

Published Reviewed 4 min readBy DSE Security Editorial Team
Read the playbook