Domain 4 · Cloud, Application, API, and Infrastructure Security
Cloud, CI/CD and Secret Exposure Analysis
Trace what a compromised build worker, pipeline credential or misconfigured cloud control can actually reach.
Decision it answers
Can our delivery path reach production without an accountable human in the way?
Inputs it needs
- Cloud configuration and posture findings
- Pipeline definitions and runner configuration
- Secret store policy and rotation records
- Approved deployment baselines and change history
Methods applied
- Reachability analysis from build context to production resources
- Secret exposure and credential leakage analysis with values redacted
- Configuration drift reconciliation against approved baselines
- Rollback and recovery path analysis
Outputs produced
- Pipeline-to-production reachability findings
- Exposed or over-scoped credential register
- Drift and unauthorized change report
- Recovery-path gaps
Must remain human-owned
Authorization, acceptance of residual risk, containment decisions, disclosure and notification, and any communication to a board or regulator. No analytical capability creates operational authority.
