Open Knowledge Project

A public Product Security field library.

The Product Security Knowledge Base turns years of practical experience into reusable guidance for engineers, architects, security leaders, and teams building modern software.

GitBook edition previewdocs.product-security.expert
Preview of the Product Security Knowledge Base GitBook interface with structured navigation, topic categories, and documentation content.
Structured navigationPractical field guidanceReusable artifacts
Open accessFree public reference
PracticalBuilt around real engineering work
ReusablePatterns, templates, and artifacts
Business-awareConnects controls to outcomes
What it covers

From security strategy to delivery detail.

The library spans the operating model around Product Security, not only individual vulnerability classes or tools.

01

Strategy & Governance

Program design, ownership, maturity, roadmaps, risk decisions, and operating cadence.

02

Secure SDLC & AppSec

Requirements, secure delivery, testing, remediation, coverage, and engineering workflows.

03

Architecture & Threat Modeling

Trust boundaries, attack paths, product design decisions, APIs, identity, and authorization.

04

DevSecOps & CI/CD

Pipeline trust, runners, secrets, security gates, artifacts, release controls, and automation.

05

Cloud & Kubernetes

AWS, IAM, workloads, containers, RBAC, networking, policies, logging, and platform risk.

06

Software Supply Chain

Dependencies, SBOM, build integrity, signing, provenance, registries, and release trust.

07

Metrics & Leadership

KPI/KRI design, engineering capacity, security debt, reporting, prioritization, and budgets.

08

Response & Validation

Vulnerability management, PSIRT thinking, evidence, technical validation, and feedback loops.

Why it exists

Useful knowledge should be easy to apply.

The project is designed to make Product Security easier to understand, implement, validate, and connect to business impact.

It also creates public accountability: prospective clients and practitioners can review the underlying thinking before deciding whether the approach fits their environment.

01Experience → patternTurn recurring engineering and leadership lessons into reusable guidance.
02Pattern → artifactPrefer checklists, examples, diagrams, templates, and decision support over abstract prose.
03Artifact → outcomeConnect security work to ownership, delivery, risk reduction, and measurable progress.
Related public work

Articles, research, and repositories around the library.

The Knowledge Base is one part of a broader proof-in-public ecosystem across Bulwark Advisory, DEV Community, and GitHub.

Explore Insights & Resources →