3Implement Secure Software Development and Compliance
- 3.1Security Policies and Rulesets
Understand defining organization and enterprise policies, strengthening the enterprise security posture and data protection, and implementing audit logging and reporting—how an admin sets org-wide guardrails.
- 3.2Repository Security Features
Understand configuring vulnerability alerts, secret scanning, and CodeQL; managing Dependabot and security advisories; and defining/implementing a security response plan—from an admin’s view.
- 3.3Managing API Access and Integrations
Understand configuring personal access tokens (PATs), rate limits for PATs and GitHub Apps, the difference between GitHub Apps and OAuth Apps, and approving/denying apps based on policy.

