ABOUT SECDOC

Security made simple.
Decisions backed by evidence.

Practical cybersecurity architecture, AI security, and the technical foundations behind secure systems.

I’m Lester Nichols, author of Cybersecurity Architect’s Handbook, Second Edition. I write for people who build, operate, and defend technology.

Free newsletter. Unsubscribe anytime.

Lester Nichols, author of Cybersecurity Architect’s Handbook
Lester NicholsAuthor · Security architect

What you’ll find here

  • Security architecture

    Identity, authorization, trust boundaries, secrets management, and recovery.

  • AI security

    Prompt injection, agent permissions, and tool access.

  • Technical foundations

    Networking, Linux, and Windows for practical security work.

  • Books and field notes

    Lessons that connect technical reading with implementation.

Experience behind the writing

More than 25 years in cybersecurity and technology, spanning government, financial services, healthcare, and IT consulting.

Author of Cybersecurity Architect’s Handbook, Second Edition, and a contributor to Computer Security Handbook.

Master’s degree in Information Assurance. Industry certifications including the CISSP.

Understand the threat. Identify the control. Verify the result.

Turn your next architecture review into a clear action plan

SECDOC · WORKSHEET PREVIEW

Security Architecture
Review Worksheet

Scope
Define the system, owner, boundaries, and important data flows.
Evidence
Record how access is controlled and which tests support that conclusion.
Actions
Assign each gap an owner, a due date, and a verification criterion.

Practical questions. Evidence you can use.

Trace important data flows, examine access decisions, record evidence gaps, and assign follow-up actions.

Join the free secdoc newsletter for new articles that help you apply this approach to cybersecurity architecture and AI security.

Subscribe free

Free newsletter. Unsubscribe anytime.

Preview three review questions
  1. Where is access authorized? Record the enforcement point, effective policy, and evidence from denied-action tests.
  2. What happens when a security dependency fails? Record expected behavior, test evidence, and who owns the response.
  3. Can the service be recovered? Record measured restore results and assign actions for unresolved recovery gaps.

Not sure where to begin?

Start with a practical guide in the area closest to your work.

Questions about my writing or professional inquiries? info@secdoc.tech