Skip to content
Curriculum 8 posts · ~1.8h total

Security & Regulatory Compliance

SOC 2, MiFID II RTS-22, and zero-trust for a crypto trading desk

Security architecture and compliance for trading firms: SOC 2 Type II audit preparation, zero-trust networking, supply chain security, credential management, insider threat controls, and MiFID II transaction reporting.

What you'll master

  • SOC 2 Type II - CC6, CC7, CC8 controls
  • Tailscale ACL zero-trust network policy
  • SLSA supply chain security + Sigstore/Cosign
  • MiFID II RTS-22 transaction reporting (81+ fields)
  • STRIDE threat modelling for crypto trading desks

Why this matters

Regulated trading infrastructure requires security controls that hold up to auditor scrutiny, not just penetration tests. These eight posts cover the gap between "we are secure" and "we can prove we are secure to a regulator, a counterparty, or an institutional investor."

The Curriculum - 8 modules