Module 1
Learn
Foundations of trustworthy software: what it means, why it matters, and how it shapes real-world engineering.
1. Working software vs trustworthy software
Working software
- The feature works
- The page loads
- The API responds
- The data is stored
Trustworthy software
- The feature works safely
- The system is secure
- Failures are visible
- Changes are traceable
- Access is controlled
- Evidence is available
2. Five pillars of trustworthy software
| Pillar | Meaning |
|---|---|
| Security | Protect systems, users, data, and access |
| Reliability | Keep the system working under expected conditions |
| Observability | Understand what is happening inside the system |
| Auditability | Prove what happened, who did it, and when |
| Compliance awareness | Align engineering practices with required controls |
Student-friendly explanation
A college project may end when the demo works. A production system begins when the team can answer: who can access it, what happens if it fails, where are the logs, can we investigate later, are secrets protected, are permissions controlled, and can we prove the system is safe enough?
3. Cloud security foundations
Shared responsibility model
AWS secures the cloud infrastructure. You secure what you build and configure on AWS.
| Area | AWS | You |
|---|---|---|
| Physical data center | AWS | — |
| Global infrastructure | AWS | — |
| IAM users and roles | — | You |
| Application code | — | You |
| Data encryption choices | Shared | Shared |
| Network configuration | — | You |
| Logging & monitoring setup | — | You |
Attack surface
All the places a system can be accessed, misused, or attacked: public APIs, login pages, IAM permissions, database access, secrets in code, public buckets, CI/CD pipelines, third-party dependencies.
Defense in depth
Do not depend on one control. Layer them: IAM + encryption + logging + monitoring + audit trail + secure deployment.
4. Secure application architecture
A basic web architecture: Frontend → API → Backend → Database. Ask the right questions at every layer.
Architecture review checklist
AuthenticationAuthorizationEncryptionLoggingMonitoringError handlingBackupLeast privilegeAudit trailCost awareness
5. Compliance as engineering evidence
Key idea
Good engineering reduces compliance pain. Poor engineering creates compliance stress.
Compliance is not only documentation — it depends on engineering practices that produce evidence: IAM policies, CloudTrail records, CloudWatch logs, Secrets Manager entries, AWS Config rules, and CI/CD deployment history.