threat model · on-behalf-of · four eyes · audit

📖 Security for Financial Systems

Notes on securing a brokerage — where money leaves through the market rather than the cashier, a filled order has no chargeback, and the most dangerous attacker is often authorised. Threat modelling, authentication, the on-behalf-of problem at the heart of authorisation, four-eyes and separation of duties, audit as a regulatory product, secrets and the exchange link, order flow as market-moving data, triaging vulnerabilities, and preserving evidence once prevention has failed.

Sources: hands-on notes from securities-system work · OWASP & NIST references · public regulatory documentation on securities-market IT.