# Defend Pillar Figures
What Defend Changes
Defend reduces dangerous authority, strengthens control boundaries, and converts remediation into retestable system changes.
Three-part figure showing qualified attack evidence, the Defend capability, and changed controls with retest criteria.
Interrupt the Paths
The highest-value control is often the chokepoint that disrupts several plausible attack paths at once.
Several attack paths converging on a shared weakness, followed by a selected control, blocked paths, and visible residual risk.
Remediation Operating Model
Security, product, platform, and engineering teams need explicit ownership for control design, implementation, and proof.
Operating model assigning risk interpretation, product decisions, platform controls, engineering implementation, and evidence signoff.
- Security
- Interpret evidence and consequence
- Prioritize control opportunities
- Define security acceptance criteria
- Platform
- Own identity, policy, and shared controls
- Provide reusable guardrails
- Instrument shared control evidence
- Product
- Own user and workflow impact
- Approve product tradeoffs
- Set rollout and exception policy
- Engineering
- Implement the system change
- Add test and evidence hooks
- Preserve regression coverage
Fix, Retest, Prove
A remediation is not complete until the control change is retested and the resulting evidence closes or updates the finding.
Governed remediation lifecycle from accepted finding through control implementation, retest, decision gate, closure, residual risk, or rework.
- 1Accept the findingConfirm scope, consequence, owner, and evidence state.
- 2Design the controlChoose the least disruptive change that addresses the supported path.
- 3Implement and instrumentChange the system and preserve the evidence needed to retest it.
- 4Retest the pathReplay the relevant conditions, alternatives, and expected controls.
- Closed
- Residual risk
- Control failed
- Inconclusive