This series treats security settings as contracts with scope and failure modes. It covers transport, headers, certificate renewal, host keys, cookies, HSTS, and certificate-authority authorization records.