Secure SDLC phases, security requirements, secure coding practices, and security testing integration for the CIA platform
Skills in this repository
Hack23/cia - Page 2
SkillsMP has collected 80 skills from Hack23/cia. Open a skill to review its source and details.
Hack23/ciaShowing 40 of 80 collected skills.
Hack23 secure development policy enforcement, SAST/DAST integration, dependency scanning, and code signing practices
Security architecture review, control validation, penetration testing guidance, and compliance verification for the CIA platform
Threat modeling before coding, STRIDE methodology, defense in depth, security controls in SDLC
Test strategy governance, coverage enforcement (80% line, 70% branch), test pyramid adherence, and CI gate enforcement
TypeScript strict mode, type safety, readonly patterns, type guards for frontend tooling used in CI/CD
Design system management, Vaadin component library patterns, consistent UI/UX, accessibility integration
Secure change control: RFC process, testing requirements, rollback procedures per ISO 27001 A.8.9, A.8.32
Implement CIS Controls v8 critical security controls for effective cyber defense in CIA platform
Implement strong encryption, secure hashing, and proper key management following NIST and OWASP cryptography guidelines
Ensure GDPR compliance for personal data processing in CIA platform with privacy-by-design principles
Implement comprehensive input validation to prevent XSS, SQL injection, and command injection attacks with sanitization strategies
Verify implementation of ISO 27001:2022 information security controls across CIA platform development and operations
Map CIA platform security controls to NIST Cybersecurity Framework functions: Identify, Protect, Detect, Respond, Recover
Never commit secrets, manage credentials securely using environment variables, vaults, and Hack23 ISMS key management policy
Conduct comprehensive security code reviews using OWASP Top 10, SAST/DAST patterns, and Hack23 ISMS secure development policy
Maintain comprehensive security documentation including SECURITY_ARCHITECTURE.md, THREAT_MODEL.md per Hack23 ISMS standards
Conduct systematic threat modeling using STRIDE framework, attack trees, and security architecture analysis for CIA platform
WCAG 2.1 AA compliance, ARIA attributes, keyboard navigation, screen reader optimization for accessible political data platforms
AWS CloudWatch metrics, alarms, dashboards, log insights, and application monitoring for the CIA platform
Business Model Canvas framework for value proposition, customer segments, revenue streams, and sustainable business model design
Chart selection, color theory, dashboard design, and data storytelling principles for political transparency data
Playwright browser automation, visual regression testing, accessibility testing, and E2E workflow validation for CIA platform
Product backlog management, user stories, acceptance criteria, sprint planning, and stakeholder management for agile development
On-page SEO, technical SEO, keyword research, and content optimization for political transparency platforms
Statistical analysis, ML, NLP, time series forecasting, network analysis for political intelligence data
Election forecasting models, campaign analysis, coalition prediction, voter behavior analysis for Swedish elections
Apply comparative politics, political behavior, public policy analysis, and democratic theory frameworks to Swedish political data
Document system architecture using C4 model: context, container, component, code diagrams per ARCHITECTURE.md
Enforce code quality with SonarCloud, CheckStyle, SpotBugs, and maintain quality gates
Follow CIA project contribution process: PR workflow, code review standards, commit conventions
Write clear technical documentation: Markdown best practices, diagrams, API docs per DOCUMENTATION_NAMING_CONVENTION.md
Implement end-to-end testing with Selenium, Playwright for CIA platform UI and workflow validation
Triage GitHub issues: labeling, prioritization, assignment, and resolution tracking
Optimize JPA/Hibernate: entity design, query performance, N+1 prevention, caching strategies
Manage multi-module Maven builds: dependencies, plugins, profiles, reproducible builds
Manage PostgreSQL: schema migrations, performance tuning, backups, monitoring per README-SCHEMA-MAINTENANCE.md
Apply Spring Framework best practices: dependency injection, transaction management, AOP for CIA services
Implement JUnit 5, Mockito, and AssertJ patterns with 80%+ code coverage for CIA platform unit tests
Design Vaadin UI components with proper lifecycle, data binding, and responsive layouts for CIA platform