Guides
Security SpecialistEngineer/DeveloperOperations & StrategyCommunity & Marketing
🔑 Key Takeaway: Guides turn framework principles into product-specific checklists. Follow the steps for each tool, then keep settings reviewed as vendors change defaults.
This section contains practical, step-by-step guides for implementing security controls across platforms and endpoints. Each guide is actionable for individuals, team members, and administrators where roles differ.
What this framework covers
- Account Management: secure communication platforms, DevOps/infrastructure accounts, and business tools.
- SSH Client and Key Management Hardening: SSH key hygiene, agent discipline, host verification.
- Hardware Security Keys: FIDO2/WebAuthn enrollment and practices.
- Password Manager Endpoint Hardening: device and endpoint controls around password vaults.
- Zoom Hardening: Zoom remote-control and meeting security posture.
Account management children
See the Account Management overview for the full product list (Discord, Telegram, Twitter/X, Signal, Slack, GitHub, GoDaddy, Render, Sentry, Vercel, Linear, Mercury, Notion, Trello).
Related frameworks
- Community Management: community-facing risks tied to these account guides
- OpSec: broader MFA, passwords, and device controls
- IAM: identity lifecycle and least privilege
- Infrastructure: DNS, hosting, and network context for registrar/DevOps guides
- User and Team Security: staff security posture (when expanded)
Further Reading
Use the linked product guides and their in-page checklists. Prefer vendor security docs for current UI paths when product surfaces change.
