Skip to content

Bedrock CybersecuritySecurity & Infrastructure Docs

One source of truth for Cirius Group — architecture, runbooks, and compliance, continuously verified against the live environment.

<div class="vp-doc" style="max-width:960px;margin:2rem auto;padding:0 1.5rem">

<SynthesisStats />

Quick reference by role

Jump straight to what you need. Live system status, current priorities, and the CI/CD pipeline reference live on the Operations &amp; Status page.

🔴 On-call / Security Engineering

LinkDescription
Incident ResponseRansomware, breaches, outages — start here
Alert TriageSources, routing, severity, escalation
Break-Glass ProcedureEmergency access for 18 accounts
Monthly Threat HuntKQL patterns and evidence retention
Out-of-Band CommsWhen primary channels are compromised
Kill Chain CoverageDetection status per stage

📋 Compliance

LinkDescription
Compliance ScorecardCurrent posture — update weekly
HIPAA ControlsFull controls matrix
SOC2 PBC GuideAuditor request mapping
Risk Assessment§164.308 formal assessment
Vendor PHI InventoryBAA status for all PHI vendors
Training LogKnowBe4, HIPAA, tabletop

🛠️ Infrastructure / Daily Ops

LinkDescription
Azure Daily OperationsRoutine Azure tasks
AWS Account AccessSSO, IAM Identity Center
Common TasksServer, firewall, cert operations
Twingate OperationsUser/resource/connector management
Arctic Wolf Day-to-DayMDR daily operations
Backup ArchitectureRSV, Veeam, offline backups

🔧 Security Architecture

LinkDescription
Threat ModelCanonical — crown jewels, threat actors, STRIDE
Palo Alto Overview4 × VM-Series, Panorama, DNS Security
Patch ManagementCadence, approval, emergency patch
Deception LayerCanary tokens + honeypots
SecOps API ReferenceEndpoints, incident lifecycle, known-good rules
Key LearningsHard-won gotchas — read before troubleshooting

</div>

Internal use only — Cirius Group