M9-04 Security Hardening — DDoS Protection¶
Milestone: M9 — Hardening and Compliance SOW Reference: NFR3, Appendix 2 milestone description Requirement Clarity: 🟡 This only appears in the Appendix 2 milestone description text, not in the formal NFR3/Appendix 6 Security Requirements list — confirm it's still a hard requirement so it's covered by the Appendix 3 acceptance criteria Dev Status: ❌ Not started
Overview¶
Protect the platform against denial-of-service attacks, per the original v3 doc's standalone requirement ("DDoS protection must be in place") and the SOW's M7-M9 milestone description.
Backend Tasks¶
- Confirm with Curo whether this is delivered via AWS-native services (Shield/CloudFront) once the AWS hosting target is decided (M4-01), or requires app-level mitigation too
Frontend Tasks¶
- N/A
Dependencies¶
- M4-01 AWS hosting decision — DDoS protection approach depends heavily on the chosen AWS service.
Acceptance Criteria¶
Not explicitly listed in Appendix 3 — worth adding an explicit criterion once scope is confirmed.
Existing Reference Material¶
None specific — general AWS security best practice.
Blockers & Risks¶
- Needs decision: confirm this is still required given its absence from the formal requirements/acceptance-criteria lists.