fanf42<p>Hello people ! I'm trying to build a 📚 <a href="https://social.treehouse.systems/tags/bibliography" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>bibliography</span></a> of research papers about 🔐<a href="https://social.treehouse.systems/tags/security" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>security</span></a> applied to <a href="https://social.treehouse.systems/tags/ops" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>ops</span></a> 🏗️💻. </p><p>The only things I have for now are old and mostly related to <a href="https://social.treehouse.systems/tags/configmanagement" class="mention hashtag" rel="nofollow noopener noreferrer" target="_blank">#<span>configmanagement</span></a> (Burgess for ex). What is the state of things? There's lots of best practices and field knowledge on patch management, items lifecycle, hardening, vuls management, observability, etc, but research? <br>The core lock always seems to be "managing the chaos of an ever changing unbelievably huge and complex human construction without compromising core security primitive which are... (resilience? A magic risk assessment metric? The classic availability/confiddntiality/integrity/traceability? What matter to ops?). Where is the research on that field that must exist somewhere? </p><p>Please help with repost or connection ❤️</p><p><a href="https://social.treehouse.systems/@fanf42/111473937507085620" translate="no" rel="nofollow noopener noreferrer" target="_blank"><span class="invisible">https://</span><span class="ellipsis">social.treehouse.systems/@fanf</span><span class="invisible">42/111473937507085620</span></a></p>