IT·Checklists
    • Web Application Security Review
    • Cloud Security Posture
    • Security Code Review
    • Secrets Management
    • Security Incident Response
    • Penetration Test Readiness
    • Production Readiness Review
    • CI/CD Pipeline Review
    • Container Image Hardening
    • Kubernetes Deployment
    • Infrastructure as Code Review
    • Release Day Runbook
    • Cloud Landing Zone Setup
    • Cloud Cost Optimisation
    • Cloud Migration Cutover
    • Serverless Readiness
    • Code Review
    • REST API Design
    • Database Schema Migration
    • New Service Bootstrap
    • Open Source Release
    • Frontend Performance
    • Web Accessibility (WCAG)
    • Observability
    • On-Call Handover
    • Incident Management
    • Postmortem
    • Backup and Recovery
    • Capacity Planning
    • Data Pipeline Review
    • Data Quality
    • ML Model Deployment
    • Data Warehouse Migration
    • Network Change
    • DNS Migration
    • TLS Certificate Management
    • Load Balancer Configuration
    • GDPR Readiness
    • ISO/IEC 27001 ISMS
    • SOC 2 Audit Readiness
    • Vendor Security Assessment
    • Employee IT Onboarding
    • Employee IT Offboarding
    • Change Management
    • Disaster Recovery Drill
    • IT Asset Management
    IT·Checklists
    • GitHub
  • to navigate
  • to select
  • to close
    • Home
    • Security
    On this page
    shield

    Security

    Application, cloud, and organisational security reviews — from a pre-release threat check to a live incident.

    security

    Web Application Security Review

    Verify a web application defends against the injection, access control, and session flaws that actually get exploited.

    admin_panel_settings

    Cloud Security Posture

    Verify the identity, network, data, and logging controls of a cloud account before and after workloads land in it.

    policy

    Security Code Review

    Verify a change introduces no new security weakness before it is merged, by reading the code with an attacker in mind.

    key

    Secrets Management

    Verify credentials are generated, stored, delivered, rotated, and revoked without ever landing in a repository or an …

    emergency

    Security Incident Response

    Verify you can detect, contain, investigate, and communicate a security incident without improvising under pressure.

    bug_report

    Penetration Test Readiness

    Verify scope, access, environment, and authorisation are settled before a penetration test starts, so the engagement …


    © 2026 IT Checklists · Built with Hugo and Lotus Docs