User and Team Security
No contributors yet. Be the first to contribute!
🔑 Key Takeaway: People-focused controls (culture, training, phishing resistance) need a dedicated home — until this framework is filled, use Security Awareness as the primary guidance. ⚠️ This article is a stub. Help expand it by contributing. Do not treat placeholder pages below as complete controls.
Why this framework exists
Web3 security failures frequently start with humans: phishing, social engineering, weak habits, and missing training. A dedicated user and team security framework should collect those practices for founders, people-ops, and security leads who are not reading deep OpSec runbooks first.
Relationship to other frameworks
| Framework | Use for |
|---|---|
| Security Awareness | Primary current content for threat recognition and mindset |
| OpSec | Device, browser, MFA, password, and travel controls |
| DPRK IT Workers | Hiring and insider-threat patterns affecting teams |
| Community Management | Discord, Telegram, and X operational security |
| Physical Security | Coercion, facilities, and physical threat models |
What this framework covers
Planned page map (stubs today — expand rather than inventing controls off-repo):
- Phishing and Social Engineering: recognition and response patterns for operators and staff.
- Security-Aware Culture: leadership norms that make secure behavior durable.
- Security Training: program design for recurring education and drills.
Expert authors should replace each stub with content that meets the content model rather than duplicating Awareness wholesale.