Trustworthy Software Lab
Resources

Resources & Glossary

A companion reference for the session and for self-study afterwards.

Session summary

Trustworthy software is more than code that runs. It is secure, reliable, observable, auditable, and compliance-aware. AWS gives you the primitives — IAM, Secrets Manager, CloudWatch, CloudTrail, and Config — but the mindset is what turns primitives into trust.

Beginner learning checklist

  1. Learn basic web application architecture
  2. Learn AWS account and IAM basics
  3. Build and deploy a simple app
  4. Add logs
  5. Remove secrets from code
  6. Learn audit trail basics
  7. Understand security checks
  8. Add CI/CD
  9. Practice DevSecOps tools
  10. Build a security-aware portfolio project

Suggested student project ideas

  • Secure event registration app
  • Student complaint tracking system
  • Placement document assistant
  • Cloud cost alert dashboard
  • Serverless URL shortener with audit logs
  • Secure file upload system
  • AI chatbot with document-grounded answers
  • DevSecOps pipeline demo project

Recommended AWS learning areas

IAM (users, roles, policies)
S3 (buckets, encryption, access)
Lambda + API Gateway
DynamoDB basics
Secrets Manager
CloudWatch (logs, metrics, alarms)
CloudTrail
AWS Config
Bedrock (for AI-native apps)

Glossary

TermDefinition
IAMIdentity and Access Management — controls who can do what in AWS.
PolicyA JSON document that grants or denies permissions.
RoleAn IAM identity assumed by services or users to get temporary permissions.
SecretSensitive value like an API key, password, or token.
LogA recorded event from your application or infrastructure.
MetricA numeric measurement over time (latency, error rate, request count).
Audit trailA record of who did what, when, and where in an account.
ComplianceProof that a system follows required rules and controls.
Config driftWhen a system moves away from its approved secure state.
Least privilegeGrant only the permissions needed to perform the task.
DevSecOpsAdding security practices into every step of software delivery.
IncidentAn unexpected event that impacts availability, security, or trust.
ObservabilityThe ability to understand system behavior from its outputs.
EncryptionTransforming data so only authorized parties can read it.
APIA defined way for programs to communicate.
ServerlessRunning code without managing servers, billed per use.
AI-native applicationAn application whose core capabilities depend on AI models.
Final takeaway
This learning app is not designed to replace AWS hands-on practice. It is designed to help students understand the security and compliance mindset before they enter a real AWS account.