10 concise reference notes for security. These are public reference material, not private user records or a transfer of language-model weights.

Least privilege

Grant a process or identity only the access needed for its authorized work. Narrow permissions reduce the scope of possible damage when a component fails or is compromised. Reassess privileges when the role changes.

Primary-source summary · ref-051

Primary reference: csrc.nist.gov

Secrets in logs

Do not print authentication cookies, recovery tokens or private request bodies by default. Use request identifiers and bounded error details for diagnosis. A log file can become a second, poorly controlled copy of sensitive data.

Authored reference note; not externally verified product advice · ref-052

Recovery credentials

A recovery key can grant access to an account and its stored data. Treat it as an authentication secret, not a harmless export identifier. Verify the association between the key and the claimed identity before restoring access.

Authored reference note; not externally verified product advice · ref-053

Ownership checks

Check private-resource ownership in server-side queries and mutation paths. Knowing a session ID, document ID or function name does not prove permission to use another account's object.

Authored reference note; not externally verified product advice · ref-054

Code and data separation

Interpret user input through a defined grammar and allowed operations. A text string supplied as data should not become unrestricted executable code. Stored programs need explicit capability boundaries and execution limits.

Authored reference note; not externally verified product advice · ref-055

Rollback safety

A rollback must account for configuration, deployed assets and data compatibility. Reverting source code alone may not recover a system after an incompatible data migration. Test the recovery path before relying on it.

Authored reference note; not externally verified product advice · ref-056

Backups and restoration

A backup is useful only when the needed data can actually be restored. Preserve ownership, access controls and version context. Keep recovery instructions with the backup and verify restoration behavior on a suitable test system.

Authored reference note; not externally verified product advice · ref-057

Origin checks

Browser-origin checks and same-site cookie behavior can help constrain cross-site requests. They do not replace account authentication or resource ownership checks. Command-line clients do not necessarily send the same headers as a browser.

Authored reference note; not externally verified product advice · ref-058

Search controls are not access controls

A robots.txt rule is crawler guidance, not protection for private data. Enforce authentication and authorization at the application. Private information should not be placed in public static pages or sitemaps.

Primary-source summary · ref-059

Primary reference: developers.google.com

Security claims

Replace absolute claims such as impossible to hack with specific controls, tested boundaries and known limits. State what was verified and in which environment. New changes and dependencies can introduce new failure paths.

Authored reference note; not externally verified product advice · ref-060

In chat, use knowledge: topic. Browse all reference topics.