<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Security Invariants on Security Blueprints</title>
    <link>https://securityblueprints.io/categories/security-invariants/</link>
    <description>Recent content in Security Invariants on Security Blueprints</description>
    <generator>Hugo</generator>
    <language>en</language>
    <managingEditor>user@example.com (Niels Provos)</managingEditor>
    <webMaster>user@example.com (Niels Provos)</webMaster>
    <copyright>Security Blueprints, LLC</copyright>
    <lastBuildDate>Sun, 06 Sep 2026 23:57:44 +0000</lastBuildDate>
    <atom:link href="https://securityblueprints.io/categories/security-invariants/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Supply Chain Aging</title>
      <link>https://securityblueprints.io/security-invariants/supply-chain-aging/</link>
      <pubDate>Fri, 01 Nov 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/security-invariants/supply-chain-aging/</guid>
      <description>Overview Supply Chain Aging is a security invariant that mandates all third-party open-source software to be aged by a specified number of days before it can be imported into the production environment. This aging period allows the community to identify and mitigate any malicious backdoors or vulnerabilities that may have been introduced into the software.&#xA;Benefits Increased Detection of Malicious Code: Significantly increases the likelihood that malicious backdoors inserted into open-source packages have been found and removed.</description>
    </item>
    <item>
      <title>Positive Execution Control</title>
      <link>https://securityblueprints.io/security-invariants/positive-execution-control/</link>
      <pubDate>Tue, 29 Oct 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/security-invariants/positive-execution-control/</guid>
      <description>Overview Positive execution control is a security invariant that enables only pre-approved (allow-listed) applications to execute on endpoints and production systems. By strictly controlling which applications can run, organizations effectively prevent unauthorized or malicious software from executing.&#xA;Benefits Malware Prevention: Stops unknown or unauthorized software from executing, thus preventing malware infections. Ransomware Protection: Prevents ransomware from executing, protecting company data from theft or irreversible loss due to unpaid ransoms. Spear Phishing Resistance: Enhances security by blocking socially engineered attacks involving the download and execution of malicious software.</description>
    </item>
    <item>
      <title>Egress Control</title>
      <link>https://securityblueprints.io/security-invariants/egress-control/</link>
      <pubDate>Mon, 28 Oct 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/security-invariants/egress-control/</guid>
      <description>Overview Egress control is a security invariant that requires all outbound network traffic from services to be explicitly allowed through domain-based allowlists. By enforcing that services can only connect to pre-approved external destinations, this security control:&#xA;Prevents exploitation of vulnerabilities that require external connectivity, e.g. to download a second stage payload. Blocks command and control (C2) traffic from compromised systems Limits data exfiltration attempts from compromised hosts Provides clear visibility into legitimate vs.</description>
    </item>
    <item>
      <title>Mandatory Hardware Second Factor</title>
      <link>https://securityblueprints.io/security-invariants/hardware-second-factor/</link>
      <pubDate>Mon, 28 Oct 2024 00:00:00 +0000</pubDate><author>user@example.com (Niels Provos)</author>
      <guid>https://securityblueprints.io/security-invariants/hardware-second-factor/</guid>
      <description>Overview A mandatory hardware second factor requires all user authentication to be completed using a physical security key, in addition to traditional passwords. This approach effectively nullifies password phishing and credential stuffing attacks.&#xA;Benefits Password Phishing Protection: Password compromise alone becomes insufficient for account access Elimination of Replay Attacks: Unlike SMS or time-based tokens, hardware keys cannot be intercepted or replayed Real-World Implementation Major technology companies have proven the effectiveness of this security invariant through comprehensive deployments:</description>
    </item>
  </channel>
</rss>
