configuration/principle/data/security.data.json
configuration/principle/data/security.data.json is a file in GovLab Context. 1054 lines of code and 0 definitions.
{
"category": "Security / Privacy / Compliance / Governance",
"check": {
"population": "every endpoint, credential, data store, permission and policy inside the trust boundary",
"freshness": "a verdict stands until the code, the policy, the configuration or the threat model changes",
"refusal": "the security gate, policy engine or secret scan fails the change or rejects the request",
"observation": "scans of source and configuration, policy decisions, and security test results",
"evidence": "none: the catalog states this check as a class, so a watched run belongs to each system that adopts it",
"authority": "the policy and the threat model, which code, configuration and requests conform to"
},
"records": [
{
"id": "security-by-design",
"distinctFrom": [
{
"id": "architecture:attack-surface-reduction",
"reason": "Security by design builds controls in from the first design, while attack surface reduction removes what nothing uses."
},
{
"id": "architecture:fail-secure",
"reason": "Security by design is the approach to every component, while fail secure is one rule, that a failed check denies access."
},
{
"id": "architecture:defense-in-depth",
"reason": "Security by design puts controls in from the start, while defense in depth layers several independent controls on each asset."
},
{
"id": "architecture:secure-by-default",
"reason": "Security by design shapes the whole design, while secure by default fixes the state its settings ship in."
}
],
"name": "Security by Design",
"definition": "A design rule that threats are modeled and controls built into every component from its first design.",
"type": "principle",
"scope": [
"system",
"service",
"codebase"
],
"requires": [
"Threat Modeling",
"Secure Defaults"
],
"reinforces": [
"Defense in Depth",
"Compliance"
],
"enables": ["Proactive Risk Reduction"],
"conflicts_with": ["Security as Afterthought"],
"tensions_with": ["Developer Ergonomics"],
"violated_by": ["lexicon:security-as-afterthought"],
"detected_by": ["missing authz/input validation/threat model"],
"measured_by": ["security control coverage"],
"refactored_by": [
"lexicon:trust-boundaries",
"architecture:input-validation",
"architecture:access-control"
],
"enforced_by": [
"security gates",
"policy-as-code"
],
"severity": "mandatory",
"exemplar": {
"before": "function createFoo(request: Request) {\n return fooStore.save(request.body as Foo);\n}",
"after": "function createFoo(request: Request, identity: Identity) {\n const input = CreateFooSchema.parse(request.body);\n authorize(identity, \"foo:create\");\n return fooStore.save(Foo.create(input));\n}",
"lang": "ts"
}
},
{
"id": "defense-in-depth",
"name": "Defense in Depth",
"definition": "A design rule that several independent security controls protect each asset, so one failed control does not expose it.",
"type": "principle",
"scope": [
"system",
"infrastructure",
"application"
],
"requires": ["Layered Controls"],
"reinforces": ["Security by Design"],
"enables": ["Compromise Containment"],
"conflicts_with": ["Single Control Reliance"],
"tensions_with": ["Complexity"],
"violated_by": ["lexicon:single-control-reliance"],
"detected_by": ["missing secondary control"],
"measured_by": ["control depth"],
"refactored_by": ["lexicon:controls"],
"enforced_by": ["threat model review"],
"severity": "mandatory",
"exemplar": {
"before": "app.post(\"/foo\", createFoo);",
"after": "app.post(\"/foo\",\n authenticate(),\n authorize(\"foo:create\"),\n validate(CreateFooSchema),\n rateLimit({ limit: 100 }),\n audit(\"FOO_CREATE\"),\n createFoo,\n);",
"lang": "ts"
}
},
{
"id": "least-privilege",
"name": "Least Privilege",
"aliases": [
"Principle of Least Privilege",
"PoLP"
],
"definition": "A design rule that each user, service and process holds only the permissions its task needs.",
"type": "principle",
"scope": [
"user",
"service",
"process",
"data"
],
"requires": [
"Access Control",
"Minimal Permissions"
],
"reinforces": [
"Zero Trust",
"Damage Limitation"
],
"enables": ["Reduced Blast Radius"],
"conflicts_with": ["Broad Admin Access"],
"tensions_with": ["Operational Convenience"],
"violated_by": ["lexicon:broad-admin-access"],
"detected_by": ["overbroad roles/scopes"],
"measured_by": ["privilege excess count"],
"refactored_by": ["lexicon:least-privilege-credential"],
"enforced_by": ["IAM policy checks"],
"severity": "mandatory",
"exemplar": {
"before": "class FooJob {\n constructor(private readonly db: AdminDatabase) {}\n run(foo: Foo) { return this.db.execute(`insert into foo values (?)`, foo); }\n}",
"after": "interface FooWriter { insert(foo: Foo): Promise<void>; }\nclass FooJob {\n constructor(private readonly foos: FooWriter) {}\n run(foo: Foo) { return this.foos.insert(foo); }\n}",
"lang": "ts"
}
},
{
"id": "zero-trust-architecture",
"name": "Zero Trust Architecture",
"aliases": ["Zero Trust"],
"definition": "A convention of authenticating and authorizing every request on its own identity and context, whatever network it comes from.",
"type": "style",
"scope": [
"system",
"network",
"identity"
],
"requires": [
"Strong Identity",
"Continuous Authorization"
],
"reinforces": ["Least Privilege"],
"enables": ["Perimeterless Security"],
"conflicts_with": ["Trusted Internal Network Assumption"],
"tensions_with": ["Latency/Complexity"],
"violated_by": ["lexicon:trusted-internal-network-assumption"],
"detected_by": ["internal endpoints without authz/authn"],
"measured_by": ["trustless control coverage"],
"refactored_by": [
"architecture:authentication",
"architecture:authorization",
"lexicon:network-segmentation"
],
"enforced_by": [
"policy-as-code",
"gateway rules"
],
"severity": "contextual",
"exemplar": {
"before": "if (request.network === \"internal\") return createFoo(request.body);",
"after": "const identity = authenticate(request.credentials);\nauthorize(identity, \"foo:create\", { resource: request.body.id });\nverifyDevice(request.deviceAttestation);\nreturn createFoo(CreateFooSchema.parse(request.body));",
"lang": "ts"
}
},
{
"id": "secure-by-default",
"distinctFrom": [
{
"id": "architecture:fail-secure",
"reason": "Secure by default is the state settings ship in, while fail secure is the state a failed check leaves access in."
},
{
"id": "lexicon:safe-defaults",
"reason": "Secure by default restricts access in the shipped settings, while safe defaults avoid harm in the shipped behavior."
}
],
"name": "Secure by Default",
"definition": "A design rule that every setting ships in its most restrictive safe state, and weakening one requires an explicit opt-in.",
"aliases": ["Secure Defaults"],
"type": "principle",
"scope": [
"configuration",
"API",
"product"
],
"requires": ["Safe Defaults"],
"reinforces": ["Fail Secure"],
"enables": ["Reduced Misconfiguration Risk"],
"conflicts_with": ["Insecure Defaults"],
"tensions_with": ["Ease of Initial Use"],
"violated_by": ["lexicon:insecure-defaults"],
"detected_by": ["insecure default config"],
"measured_by": ["insecure default count"],
"refactored_by": ["lexicon:default-deny"],
"enforced_by": ["config policy"],
"severity": "mandatory",
"exemplar": {
"before": "const fooApi = createApi({ public: true, tls: false, audit: false });",
"after": "const fooApi = createApi({\n public: false,\n tls: \"required\",\n authentication: \"required\",\n audit: true,\n});",
"lang": "ts"
}
},
{
"id": "attack-surface-reduction",
"name": "Attack Surface Reduction",
"definition": "A design rule that endpoints, ports, features and permissions nothing uses are removed or disabled.",
"type": "principle",
"scope": [
"API",
"service",
"infrastructure"
],
"requires": ["Minimal Exposure"],
"reinforces": ["Security by Design"],
"enables": ["Reduced Exploitability"],
"conflicts_with": ["Unnecessary Public Surface"],
"tensions_with": ["Feature Exposure"],
"violated_by": ["lexicon:unnecessary-public-surface"],
"detected_by": ["exposed unused routes/services"],
"measured_by": ["exposed surface count"],
"refactored_by": [
"lexicon:restrict-exports",
"architecture:access-control",
"architecture:feature-toggle"
],
"enforced_by": ["attack surface scanning"],
"severity": "mandatory",
"exemplar": {
"before": "app.enableDebugConsole();\napp.exposeAdminApi();\napp.loadAllPlugins();",
"after": "app.register(fooPublicApi);\napp.disable(\"debug-console\");\napp.disable(\"admin-api\");\napp.loadPlugins(approvedFooPlugins);",
"lang": "ts"
}
},
{
"id": "threat-modeling",
"distinctFrom": [
{
"id": "lexicon:control-selection",
"reason": "Threat modeling lists the assets, boundaries and threats, while control selection chooses the controls that answer them."
}
],
"name": "Threat Modeling",
"definition": "The activity of listing a flow's assets, trust boundaries and threats, and choosing a mitigation for each threat.",
"type": "activity",
"scope": [
"feature",
"system",
"architecture"
],
"requires": [
"Assets",
"Trust Boundaries",
"Threat Scenarios"
],
"reinforces": [
"Security by Design",
"Risk Management"
],
"enables": ["Control Selection"],
"conflicts_with": [
"Assumption-Driven Security",
"Security Theater"
],
"tensions_with": ["Delivery Speed"],
"violated_by": ["lexicon:assumption-driven-security"],
"detected_by": ["missing threat model for sensitive flow"],
"measured_by": ["threat model coverage"],
"refactored_by": ["lexicon:mitigation-plan"],
"enforced_by": ["security review gates"],
"severity": "contextual",
"mandatoryFor": "sensitive systems",
"exemplar": {
"before": "designFooUpload();\nshipFooUpload();",
"after": "const threats = modelThreats(fooUploadFlow, [\"spoofing\", \"tampering\", \"repudiation\", \"disclosure\", \"denial\", \"elevation\"]);\nfor (const threat of threats) requireMitigation(threat);\nshipFooUpload();",
"lang": "ts"
}
},
{
"id": "authentication",
"distinctFrom": [
{
"id": "architecture:access-control",
"reason": "Authentication verifies who the caller is, while access control decides what that caller may do."
},
{
"id": "architecture:csrf-protection",
"reason": "Authentication verifies an identity, while CSRF protection verifies that a request came from the site's own pages."
},
{
"id": "architecture:session-management",
"reason": "Authentication verifies a credential once, while session management keeps the result across requests."
}
],
"name": "Authentication",
"definition": "A mechanism that verifies a caller's claimed identity from a credential before any protected action runs.",
"type": "mechanism",
"scope": [
"user",
"service",
"API"
],
"requires": ["Identity Proof"],
"reinforces": ["Access Control"],
"enables": ["Identity-Aware Authorization"],
"conflicts_with": ["Anonymous Sensitive Access"],
"tensions_with": ["UX"],
"violated_by": ["lexicon:anonymous-sensitive-access"],
"detected_by": ["unauthenticated protected endpoints"],
"measured_by": ["auth coverage"],
"refactored_by": [],
"enforced_by": [
"route policies",
"tests"
],
"severity": "mandatory",
"exemplar": {
"before": "const userId = request.headers.get(\"X-User-ID\");\nreturn loadFooFor(userId!);",
"after": "const credential = requireHeader(request, \"Authorization\");\nconst identity = await authenticator.verify(credential);\nif (!identity) throw new UnauthorizedError();\nreturn loadFooFor(identity.subject);",
"lang": "ts"
}
},
{
"id": "authorization",
"distinctFrom": [
{
"id": "lexicon:remote-stub",
"reason": "Authorization decides whether a principal may act, while a remote stub forwards calls to an object in another process."
}
],
"name": "Authorization",
"definition": "A mechanism that decides, from a policy, whether an authenticated principal may perform an action on a resource.",
"type": "mechanism",
"scope": [
"API",
"domain action",
"data access"
],
"requires": [
"Authenticated Principal",
"Policy"
],
"reinforces": ["Least Privilege"],
"enables": ["Controlled Access"],
"conflicts_with": [
"Authenticated-Equals-Authorized",
"Authorization Scattering"
],
"tensions_with": ["Policy Complexity"],
"violated_by": ["lexicon:unrestricted-access"],
"detected_by": ["protected operation without authz guard"],
"measured_by": ["authorization coverage"],
"refactored_by": [
"architecture:policy-enforcement",
"lexicon:centralize-policy"
],
"enforced_by": [
"security tests",
"policy-as-code"
],
"severity": "mandatory",
"exemplar": {
"before": "const identity = authenticate(request);\nreturn fooStore.delete(request.params.id);",
"after": "const identity = authenticate(request);\nauthorize(identity, \"foo:delete\", { fooId: request.params.id });\nreturn fooStore.delete(request.params.id);",
"lang": "ts"
}
},
{
"id": "access-control",
"distinctFrom": [
{
"id": "architecture:session-management",
"reason": "Access control evaluates a policy per request, while session management keeps the authenticated session the request carries."
},
{
"id": "lexicon:config-store",
"reason": "Access control decides who may reach a resource, while a config store is one such resource, holding configuration for many services."
}
],
"name": "Access Control",
"definition": "A mechanism that evaluates an access policy for each request to a resource and denies the request when the policy does not allow it.",
"canon": ["access-control"],
"type": "mechanism",
"scope": [
"API",
"data",
"infrastructure"
],
"requires": ["Authorization Policy"],
"reinforces": ["Least Privilege"],
"enables": ["Resource Protection"],
"conflicts_with": ["Unrestricted Access"],
"tensions_with": ["Usability"],
"violated_by": ["lexicon:unrestricted-access"],
"detected_by": ["resource endpoint lacking policy"],
"measured_by": ["access control coverage"],
"refactored_by": [],
"enforced_by": ["policy tests"],
"severity": "mandatory",
"exemplar": {
"before": "if (user.role === \"admin\") return fooStore.findAll();",
"after": "const decision = accessPolicy.evaluate({\n subject: user,\n action: \"foo:list\",\n resource: { tenantId: request.tenantId },\n});\nif (!decision.allowed) throw new ForbiddenError();\nreturn fooStore.findAll(request.tenantId);",
"lang": "ts"
}
},
{
"id": "role-based-access-control",
"name": "Role-Based Access Control (RBAC)",
"aliases": ["RBAC"],
"definition": "A conceptual representation of access control, Role-Based Access Control (RBAC), in which permissions attach to roles and users receive roles.",
"type": "model",
"scope": [
"user",
"role",
"resource"
],
"requires": ["Role Definitions"],
"reinforces": ["Access Control"],
"enables": ["Coarse-Grained Permission Management"],
"conflicts_with": ["Ad-Hoc Permission Checks"],
"tensions_with": ["Role Explosion"],
"violated_by": ["lexicon:hardcoded-rules"],
"detected_by": ["scattered role checks"],
"measured_by": ["role-policy consistency"],
"refactored_by": ["lexicon:centralize-policy"],
"enforced_by": ["authorization tests"],
"severity": "contextual",
"exemplar": {
"before": "if (user.name === \"Developer\") allowDeleteFoo();",
"after": "const roles = new Map([\n [\"foo-reader\", [\"foo:read\"]],\n [\"foo-editor\", [\"foo:read\", \"foo:write\"]],\n [\"foo-admin\", [\"foo:read\", \"foo:write\", \"foo:delete\"]],\n]);\nauthorizeRole(user.roles, \"foo:delete\", roles);",
"lang": "ts"
}
},
{
"id": "attribute-based-access-control",
"name": "Attribute-Based Access Control (ABAC)",
"aliases": ["ABAC"],
"definition": "A conceptual representation of access control, Attribute-Based Access Control (ABAC), in which a policy decides from attributes of the subject, the resource and the environment.",
"type": "model",
"scope": [
"user",
"resource",
"context"
],
"requires": [
"Attribute Definitions",
"Policy Engine"
],
"reinforces": ["Fine-Grained Access Control"],
"enables": ["Context-Aware Authorization"],
"conflicts_with": ["Hardcoded Rules"],
"tensions_with": ["Policy Complexity"],
"violated_by": ["lexicon:hardcoded-rules"],
"detected_by": ["duplicated attribute checks in handlers"],
"measured_by": ["policy centralization"],
"refactored_by": [
"architecture:policy-as-code",
"lexicon:policy-engine"
],
"enforced_by": ["policy-as-code"],
"severity": "contextual",
"exemplar": {
"before": "if (user.role === \"editor\") return updateFoo(foo);",
"after": "const decision = policy.evaluate({\n subject: { id: user.id, department: user.department },\n action: \"foo:update\",\n resource: { ownerId: foo.ownerId, classification: foo.classification },\n environment: { time: clock.now() },\n});\nif (!decision.allowed) throw new ForbiddenError();",
"lang": "ts"
}
},
{
"id": "input-validation",
"name": "Input Validation",
"definition": "A mechanism that checks external input against a schema at the boundary before core logic uses it.",
"canon": ["input-validation"],
"type": "mechanism",
"scope": [
"API",
"boundary",
"function"
],
"requires": [
"Validation Rules",
"Schema"
],
"reinforces": [
"Security",
"Correctness"
],
"enables": ["Fail Fast"],
"conflicts_with": ["Trusting External Input"],
"tensions_with": ["Input Flexibility"],
"violated_by": ["lexicon:trusting-external-input"],
"detected_by": ["missing boundary validators"],
"measured_by": ["validation coverage"],
"refactored_by": ["architecture:schema-validation"],
"enforced_by": [
"validation middleware",
"tests"
],
"severity": "mandatory",
"exemplar": {
"before": "const input = request.body as Foo;\nfooStore.save(input);",
"after": "const input = CreateFooSchema.parse(request.body);\nfooStore.save(input);",
"lang": "ts"
}
},
{
"id": "output-encoding",
"name": "Output Encoding",
"definition": "A mechanism that escapes values for the context they are written into, such as HTML, SQL or a shell.",
"type": "mechanism",
"scope": [
"UI",
"API",
"serialization"
],
"requires": ["Context-Aware Encoding"],
"reinforces": ["Injection Prevention"],
"enables": ["Safe Rendering"],
"conflicts_with": ["Raw Output Rendering"],
"tensions_with": ["Formatting Flexibility"],
"violated_by": ["lexicon:raw-output-rendering"],
"detected_by": ["raw HTML/SQL/shell output paths"],
"measured_by": ["unsafe sink count"],
"refactored_by": ["lexicon:context-aware-encoding"],
"enforced_by": ["security linting"],
"severity": "mandatory",
"exemplar": {
"before": "response.html(`<div>${foo.name}</div>`);",
"after": "response.html(`<div>${escapeHtml(foo.name)}</div>`);",
"lang": "ts"
}
},
{
"id": "encryption-at-rest",
"name": "Encryption at Rest",
"definition": "A mechanism that encrypts stored data with managed keys, so the storage medium alone does not reveal it.",
"canon": ["encryption-at-rest"],
"type": "mechanism",
"scope": [
"storage",
"database",
"backups"
],
"requires": ["Key Management"],
"reinforces": ["Data Protection"],
"enables": ["Confidentiality of Stored Data"],
"conflicts_with": ["Plaintext Sensitive Storage"],
"tensions_with": ["Key Operations"],
"violated_by": ["lexicon:plaintext-sensitive-storage"],
"detected_by": ["storage config scan"],
"measured_by": ["encrypted storage coverage"],
"refactored_by": ["lexicon:key-management"],
"enforced_by": ["infrastructure policy"],
"severity": "contextual",
"mandatoryFor": "sensitive data",
"exemplar": {
"before": "await disk.write(\"foos.json\", JSON.stringify(foos));",
"after": "const ciphertext = await keyManager.encrypt(\"foo-data-key\", JSON.stringify(foos));\nawait disk.write(\"foos.enc\", ciphertext);",
"lang": "ts"
}
},
{
"id": "encryption-in-transit",
"distinctFrom": [
{
"id": "lexicon:tls-mtls",
"reason": "Encryption in transit is the practice of encrypting traffic and verifying peers, while TLS and mutual TLS are the protocols that do it."
}
],
"name": "Encryption in Transit",
"definition": "A mechanism that encrypts traffic between parties with TLS or mutual TLS and verifies the peer's certificate.",
"canon": ["encryption-in-transit"],
"type": "mechanism",
"scope": [
"network",
"service communication"
],
"requires": ["TLS/mTLS"],
"reinforces": [
"Confidentiality",
"Integrity"
],
"enables": ["Secure Communication"],
"conflicts_with": ["Plaintext Transport"],
"tensions_with": ["Certificate Management"],
"violated_by": ["lexicon:plaintext-transport"],
"detected_by": ["HTTP/plain socket usage"],
"measured_by": ["encrypted transport coverage"],
"refactored_by": ["lexicon:tls-mtls"],
"enforced_by": ["gateway/network policy"],
"severity": "mandatory",
"exemplar": {
"before": "const client = new HttpClient(\"http://foo.internal\");",
"after": "const client = new HttpClient(\"https://foo.internal\", {\n tls: { minVersion: \"TLSv1.3\", verifyPeer: true },\n});",
"lang": "ts"
}
},
{
"id": "secrets-management",
"name": "Secrets Management",
"definition": "The practice of keeping credentials in a secret store, reading them at runtime and rotating them on a schedule.",
"type": "activity",
"scope": [
"config",
"deployment",
"runtime"
],
"requires": [
"Secret Store",
"Rotation Policy"
],
"reinforces": ["Secure Configuration"],
"enables": ["Safe Credential Handling"],
"conflicts_with": [
"Hardcoded Secrets",
"Secret Sprawl"
],
"tensions_with": ["Operational Complexity"],
"violated_by": [
"architecture:secret-sprawl",
"lexicon:hardcoded-secrets"
],
"detected_by": ["secret scanning"],
"measured_by": ["secret exposure count"],
"refactored_by": ["lexicon:secret-rotation"],
"enforced_by": [
"secret scans",
"CI gates"
],
"severity": "mandatory",
"exemplar": {
"before": "const fooClient = new FooClient({ apiKey: \"foo_live_abc123\" });",
"after": "const apiKey = await secretStore.read(\"services/foo/api-key\");\nif (!apiKey) throw new Error(\"missing foo api key\");\nconst fooClient = new FooClient({ apiKey });",
"lang": "ts"
}
},
{
"id": "privacy-by-design",
"distinctFrom": [
{
"id": "lexicon:data-minimization",
"reason": "Privacy by design covers collection, retention, visibility and defaults from the first version, while data minimization is its collection and retention part."
}
],
"name": "Privacy by Design",
"definition": "A design rule that privacy protection is part of a system's design from its first version, covering which personal data it collects, how long it keeps it, who can see it and what its defaults expose.",
"type": "principle",
"scope": [
"data",
"product",
"system"
],
"requires": [
"Data Minimization",
"Consent/Policy"
],
"reinforces": [
"Compliance",
"Security"
],
"enables": ["Privacy Compliance"],
"conflicts_with": [
"Unbounded Data Collection",
"Personal Data Oversharing"
],
"tensions_with": ["Analytics/Personalization"],
"violated_by": ["architecture:personal-data-oversharing"],
"detected_by": ["personal-data flow without policy"],
"measured_by": [
"personal-data surface",
"retention compliance"
],
"refactored_by": [
"lexicon:purpose-binding",
"lexicon:retention-policy"
],
"enforced_by": [
"privacy review",
"policy-as-code"
],
"severity": "contextual",
"mandatoryFor": "systems holding personal data",
"exemplar": {
"before": "auditLog.append({ user, request, foo, headers: request.headers });",
"after": "auditLog.append({\n actorId: pseudonymize(user.id),\n action: \"FOO_READ\",\n fooId: foo.id,\n purpose: \"support\",\n});",
"lang": "ts"
}
},
{
"id": "compliance",
"name": "Compliance",
"definition": "A rule or precondition that a system implements the controls a regulation or standard requires, and keeps evidence of each one.",
"type": "constraint",
"scope": [
"system",
"organization",
"process"
],
"requires": [
"Controls",
"Evidence",
"Auditability"
],
"reinforces": [
"Governance",
"Risk Management"
],
"enables": ["Regulatory Alignment"],
"conflicts_with": ["Uncontrolled Change"],
"tensions_with": ["Delivery Speed"],
"violated_by": ["lexicon:point-in-time-audit-only"],
"detected_by": ["compliance gap assessment"],
"measured_by": ["control pass rate"],
"refactored_by": [
"lexicon:controls",
"lexicon:evidence-citation"
],
"enforced_by": ["compliance gates"],
"severity": "contextual",
"mandatoryFor": "regulated systems",
"exemplar": {
"before": "storeFooData(foo);",
"after": "const classified = classify(foo);\nconst controls = compliance.requirements(classified, \"foo-storage\");\nawait enforceControls(controls);\nawait storeFooData(foo);",
"lang": "ts"
}
},
{
"id": "governance",
"distinctFrom": [
{
"id": "architecture:decentralization",
"reason": "Governance holds decisions to shared policy, while decentralization leaves them with the owning teams."
},
{
"id": "architecture:standardization",
"reason": "Governance reviews and gates decisions against policy, while standardization is one policy it can enforce, one choice per concern."
}
],
"name": "Governance",
"definition": "A design rule that architecture decisions are held to stated policies and standards, through review and automated gates.",
"type": "principle",
"scope": [
"organization",
"architecture",
"platform"
],
"requires": [
"Policy",
"Standards",
"Review"
],
"reinforces": [
"Compliance",
"Consistency"
],
"enables": ["Controlled Evolution"],
"conflicts_with": ["Unbounded Autonomy"],
"tensions_with": ["Team Velocity"],
"violated_by": ["lexicon:uncontrolled-change"],
"detected_by": [
"standard violations",
"undocumented decisions"
],
"measured_by": ["policy compliance"],
"refactored_by": [
"lexicon:standardize-the-interface",
"architecture:design-review"
],
"enforced_by": [
"architecture board",
"policy-as-code"
],
"severity": "contextual",
"exemplar": {
"before": "teams.defineFooApisIndependently();",
"after": "const governance = defineArchitecturePolicy({\n apiVersioning: \"required\",\n schemaRegistry: \"required\",\n ownership: \"single-team\",\n});\narchitectureGate.enforce(governance);",
"lang": "ts"
}
},
{
"id": "policy-enforcement",
"name": "Policy Enforcement",
"definition": "A mechanism that blocks an action a policy forbids at the point the action is attempted.",
"type": "mechanism",
"scope": [
"code",
"infrastructure",
"runtime"
],
"requires": ["Defined Policy"],
"reinforces": [
"Compliance",
"Security"
],
"enables": ["Automated Control"],
"conflicts_with": ["Manual-Only Review"],
"tensions_with": ["False Positives"],
"violated_by": ["architecture:manual-only-governance"],
"detected_by": ["policy drift"],
"measured_by": ["policy violation count"],
"refactored_by": [
"architecture:policy-as-code",
"architecture:fitness-functions"
],
"enforced_by": [
"CI/CD",
"runtime policy engine"
],
"severity": "mandatory",
"exemplar": {
"before": "if (!policyAllows(user, foo)) fooLog.record(\"policy violation\");\nreturn updateFoo(foo);",
"after": "if (!policyAllows(user, foo)) throw new ForbiddenError();\nreturn updateFoo(foo);",
"lang": "ts"
}
},
{
"id": "policy-as-code",
"name": "Policy as Code",
"definition": "A mechanism that expresses policies as machine-readable rules which a pipeline or policy engine evaluates automatically.",
"type": "mechanism",
"scope": [
"infrastructure",
"deployment",
"security"
],
"requires": ["Machine-Readable Policies"],
"reinforces": ["Continuous Compliance"],
"enables": ["Automated Enforcement"],
"conflicts_with": [
"Document-Only Policy",
"Manual-Only Governance"
],
"tensions_with": ["Policy Maintenance"],
"violated_by": ["lexicon:manual-only-review"],
"detected_by": ["missing policy rule for known control"],
"measured_by": ["automated policy coverage"],
"refactored_by": ["architecture:fitness-functions"],
"enforced_by": ["policy engine"],
"severity": "recommended",
"exemplar": {
"before": "document.write(\"Only foo-admin may delete Foo\");",
"after": "const fooDeletePolicy = policy({\n action: \"foo:delete\",\n allow: input => input.subject.roles.includes(\"foo-admin\"),\n});\npolicyGate.enforce(fooDeletePolicy);",
"lang": "ts"
}
},
{
"id": "risk-management",
"distinctFrom": [
{
"id": "lexicon:mitigation",
"reason": "Risk management is the whole cycle of identifying, rating and owning risks, while mitigation is the step that reduces one."
},
{
"id": "lexicon:risk-identification",
"reason": "Risk management runs the whole cycle, while risk identification is its first step, finding the risks."
},
{
"id": "architecture:threat-modeling",
"reason": "Risk management covers every kind of risk, while threat modeling covers the security threats to one flow."
}
],
"name": "Risk Management",
"definition": "The activity of identifying risks, rating their likelihood and impact, and assigning each one an owner and a mitigation.",
"type": "activity",
"scope": [
"architecture",
"security",
"delivery"
],
"requires": [
"Risk Identification",
"Mitigation"
],
"reinforces": [
"Compliance",
"Security by Design"
],
"enables": ["Priority-Based Controls"],
"conflicts_with": [
"Unknown/Unowned Risk",
"Unowned Risk"
],
"tensions_with": ["Speed"],
"violated_by": ["architecture:unowned-risk"],
"detected_by": ["risk register gaps"],
"measured_by": ["residual risk score"],
"refactored_by": [
"lexicon:mitigation-plan",
"lexicon:restrict-exports"
],
"enforced_by": ["review gates"],
"severity": "contextual",
"exemplar": {
"before": "shipFooFeature();",
"after": "const risk = assessRisk(fooFeature, {\n likelihood: 3,\n impact: 5,\n controls: [\"rate-limit\", \"audit\", \"rollback\"],\n});\nif (risk.residual > riskTolerance) throw new Error(\"risk not accepted\");\nshipFooFeature();",
"lang": "ts"
}
},
{
"id": "continuous-compliance",
"distinctFrom": [
{
"id": "lexicon:evidence-automation",
"reason": "Continuous compliance checks every change against policy, while evidence automation collects the proof that the checks ran."
},
{
"id": "lexicon:ongoing-assurance",
"reason": "Continuous compliance is checking on every change, while ongoing assurance is being able to show at any time that controls still work."
}
],
"name": "Continuous Compliance",
"definition": "The ability to check compliance on every change, with automated policy gates and evidence capture.",
"type": "capability",
"scope": [
"CI/CD",
"infrastructure",
"codebase"
],
"requires": [
"Policy as Code",
"Evidence Automation"
],
"reinforces": [
"Compliance",
"Auditability"
],
"enables": ["Ongoing Assurance"],
"conflicts_with": ["Point-in-Time Audit Only"],
"tensions_with": ["Pipeline Complexity"],
"violated_by": ["lexicon:point-in-time-audit-only"],
"detected_by": ["missing automated compliance checks"],
"measured_by": ["continuous control pass rate"],
"refactored_by": [
"lexicon:automated-enforcement",
"architecture:policy-as-code"
],
"enforced_by": ["CI/CD controls"],
"severity": "contextual",
"exemplar": {
"before": "runComplianceAuditOncePerYear();",
"after": "pipeline.on(\"change\", async change => {\n const result = await complianceScanner.evaluate(change);\n if (!result.compliant) throw new ComplianceGateError(result.violations);\n});",
"lang": "ts"
}
},
{
"id": "csrf-protection",
"name": "CSRF Protection",
"aliases": ["Cross-Site Request Forgery Protection"],
"definition": "A mechanism that rejects state-changing requests which lack proof of coming from the site's own pages, such as an anti-forgery token.",
"type": "mechanism",
"scope": [
"service",
"web",
"security"
],
"requires": ["Request Origin Verification"],
"reinforces": [
"Authentication",
"Defense in Depth"
],
"enables": ["Forged-Request Rejection"],
"conflicts_with": ["Ambient-Credential Trust"],
"tensions_with": ["Client Complexity"],
"violated_by": ["lexicon:ambient-credential-trust"],
"detected_by": ["no anti-forgery token on mutating endpoints"],
"measured_by": ["unprotected state-changing endpoint count"],
"refactored_by": [],
"enforced_by": ["security review"],
"severity": "contextual",
"mandatoryFor": "public APIs",
"exemplar": {
"before": "app.post(\"/foo/delete\", deleteFoo);",
"after": "app.post(\"/foo/delete\", verifyCsrfToken(), requireSameSite(), deleteFoo);",
"lang": "ts"
}
},
{
"id": "parameterized-queries",
"distinctFrom": [
{
"id": "architecture:input-validation",
"reason": "Parameterized queries keep values out of query syntax whatever they contain, while input validation checks what values contain before use."
}
],
"name": "Parameterized Queries",
"definition": "A mechanism that sends query text and values to the database separately, so values are never parsed as query syntax.",
"type": "mechanism",
"scope": [
"service",
"database",
"security"
],
"requires": ["Query Parameter Binding"],
"reinforces": [
"Input Validation",
"Secure by Default"
],
"enables": ["Injection-Safe Data Access"],
"conflicts_with": ["String-Concatenated SQL"],
"tensions_with": ["Dynamic Query Flexibility"],
"violated_by": ["lexicon:string-concatenated-sql"],
"detected_by": ["string interpolation into query text"],
"measured_by": ["concatenated-query count"],
"refactored_by": [],
"enforced_by": ["security review"],
"severity": "mandatory",
"exemplar": {
"before": "db.query(`select * from foos where id = '${id}'`);",
"after": "db.query(\"select * from foos where id = $1\", [id]);",
"lang": "ts"
}
},
{
"id": "session-management",
"name": "Session Management",
"definition": "A mechanism that keeps authenticated sessions on the server, with expiry, rotation and revocation, and gives the client only an opaque identifier.",
"type": "mechanism",
"scope": [
"service",
"authentication",
"security"
],
"requires": ["Authentication"],
"reinforces": [
"Access Control",
"Least Privilege"
],
"enables": [
"Bounded Session Lifetime",
"Revocable Access"
],
"conflicts_with": ["Immortal Client-Trusted Session"],
"tensions_with": ["User Convenience"],
"violated_by": ["lexicon:immortal-client-trusted-session"],
"detected_by": ["no expiry/rotation/revocation on sessions"],
"measured_by": ["unbounded-session count"],
"refactored_by": [],
"enforced_by": ["security review"],
"severity": "contextual",
"mandatoryFor": "sensitive systems",
"exemplar": {
"before": "res.cookie(\"userId\", user.id);",
"after": "const session = await sessions.create(user.id, { ttlMs: 3_600_000, rotateOnAuth: true });\nres.cookie(\"sid\", session.id, { httpOnly: true, secure: true, sameSite: \"strict\" });",
"lang": "ts"
}
}
]
}