ABOUT SECDOC
Security made simple.
Decisions backed by evidence.
Practical cybersecurity architecture, AI security, and the technical foundations behind secure systems.
I’m Lester Nichols, author of Cybersecurity Architect’s Handbook, Second Edition. I write for people who build, operate, and defend technology.
Free newsletter. Unsubscribe anytime.
What you’ll find here
Security architecture
Identity, authorization, trust boundaries, secrets management, and recovery.
AI security
Prompt injection, agent permissions, and tool access.
Technical foundations
Networking, Linux, and Windows for practical security work.
Books and field notes
Lessons that connect technical reading with implementation.
Experience behind the writing
More than 25 years in cybersecurity and technology, spanning government, financial services, healthcare, and IT consulting.
Author of Cybersecurity Architect’s Handbook, Second Edition, and a contributor to Computer Security Handbook.
Master’s degree in Information Assurance. Industry certifications including the CISSP.
Understand the threat. Identify the control. Verify the result.
Turn your next architecture review into a clear action plan
SECDOC · WORKSHEET PREVIEW
Security Architecture
Review Worksheet
- Scope
- Define the system, owner, boundaries, and important data flows.
- Evidence
- Record how access is controlled and which tests support that conclusion.
- Actions
- Assign each gap an owner, a due date, and a verification criterion.
Practical questions. Evidence you can use.
Trace important data flows, examine access decisions, record evidence gaps, and assign follow-up actions.
Join the free secdoc newsletter for new articles that help you apply this approach to cybersecurity architecture and AI security.
Subscribe freeFree newsletter. Unsubscribe anytime.
Preview three review questions
- Where is access authorized? Record the enforcement point, effective policy, and evidence from denied-action tests.
- What happens when a security dependency fails? Record expected behavior, test evidence, and who owns the response.
- Can the service be recovered? Record measured restore results and assign actions for unresolved recovery gaps.
Not sure where to begin?
Start with a practical guide in the area closest to your work.
Questions about my writing or professional inquiries? info@secdoc.tech