Security check

Twelve questions for a small engineering team. Five are about how you deliver software. Seven are about the fundamentals underneath it.

None of them ask what your policy is, because a policy is free. They ask for something that happened, or for a number you either know or do not. That is the point. Answer for the company you have, not the one you are building towards.

Nothing is sent anywhere. There is no request, no cookie and no storage. Everything is calculated in your browser, and closing the tab discards it.

Delivery

Five questions about the last time, not the usual time.

1. The last time you had to apply an urgent security patch, how long was it from the fix being available to it running in production?
2. What is the longest interval between two production deployments in the last month?
3. Take your last merged pull request. How long was it from the merge to production?
4. Of your last ten production deployments, how many needed a correction within 24 hours?
5. At your last production incident, how long was the service unusable?

Fundamentals

Seven questions. “I do not know” is a real answer and it counts for something.

6. Can you list, within ten minutes, everything an attacker gets if they own your CI?
7. Is there a single action that removes a person from access to everything?
8. Has a machine restored one of your backups in the last ninety days?
9. Would you merge a dependency bump nobody read, on the strength of your test suite alone?
10. Are you current enough to take an emergency patch this week?
11. Is everything in your stack trusted for a reason other than where it sits on the network?
12. Does every production change have an author, a reviewer and a revert?