The Ministry’s CSIRT platform serves two distinct needs: accessible public information and protected internal work for administrators and assessment teams.
What was getting in the way.
Public visitors and internal teams need very different levels of access, even though their information and workflows belong to the same service platform.
Turning the process into a usable system.
- Built and maintained public content, administration, secure access, and role-based internal workflows.
- Connected an internal application inventory and assessment module to the main platform.
- Supported the live service across deployment, access, and integration issues.
- Worked with government stakeholders to review requirements and delivery progress.
A simple view of people, process, and information.
This simplified view only shows verified parts of the service. Confidential access, infrastructure details, and operational data are intentionally omitted.
The public portal and protected assessment module needed to work as one service without exposing internal records or creating a confusing sign-in journey.
I aligned access rules and the connection between both applications, then supported the production setup until the full journey worked reliably.
- Clear separation of public and protected work
- Role-based administration
- Application inventory and assessment records
- Search, sorting, import, and export
- Production operation across connected applications
What changed for the people using it.
- The official CSIRT public portal remains available in production.
- Internal teams gained protected search, import, export, and assessment workflows.
- Public information and internal operations can coexist with appropriate access boundaries.
Private enterprise application — source code, credentials, internal endpoints, and production access are confidential.
