# Architecture principles whose category is Security / Privacy / Compliance / Governance

> 27 records

This index as JSON: https://banes-lab.com/json/api/facets/architecture/category/security-privacy-compliance-governance

## Entries

- [Security by Design](https://banes-lab.com/records/architecture/security-by-design.md): A design rule that threats are modeled and controls built into every component from its first design.
- [Defense in Depth](https://banes-lab.com/records/architecture/defense-in-depth.md): A design rule that several independent security controls protect each asset, so one failed control does not expose it.
- [Least Privilege](https://banes-lab.com/records/architecture/least-privilege.md): A design rule that each user, service and process holds only the permissions its task needs.
- [Zero Trust Architecture](https://banes-lab.com/records/architecture/zero-trust-architecture.md): A convention of authenticating and authorizing every request on its own identity and context, whatever network it comes from.
- [Secure by Default](https://banes-lab.com/records/architecture/secure-by-default.md): A design rule that every setting ships in its most restrictive safe state, and weakening one requires an explicit opt-in.
- [Attack Surface Reduction](https://banes-lab.com/records/architecture/attack-surface-reduction.md): A design rule that endpoints, ports, features and permissions nothing uses are removed or disabled.
- [Threat Modeling](https://banes-lab.com/records/architecture/threat-modeling.md): The activity of listing a flow's assets, trust boundaries and threats, and choosing a mitigation for each threat.
- [Authentication](https://banes-lab.com/records/architecture/authentication.md): A mechanism that verifies a caller's claimed identity from a credential before any protected action runs.
- [Authorization](https://banes-lab.com/records/architecture/authorization.md): A mechanism that decides, from a policy, whether an authenticated principal may perform an action on a resource.
- [Access Control](https://banes-lab.com/records/architecture/access-control.md): A mechanism that evaluates an access policy for each request to a resource and denies the request when the policy does not allow it.
- [RBAC](https://banes-lab.com/records/architecture/role-based-access-control.md): A conceptual representation of access control, Role-Based Access Control (RBAC), in which permissions attach to roles and users receive roles.
- [ABAC](https://banes-lab.com/records/architecture/attribute-based-access-control.md): A conceptual representation of access control, Attribute-Based Access Control (ABAC), in which a policy decides from attributes of the subject, the resource and the environment.
- [Input Validation](https://banes-lab.com/records/architecture/input-validation.md): A mechanism that checks external input against a schema at the boundary before core logic uses it.
- [Output Encoding](https://banes-lab.com/records/architecture/output-encoding.md): A mechanism that escapes values for the context they are written into, such as HTML, SQL or a shell.
- [Encryption at Rest](https://banes-lab.com/records/architecture/encryption-at-rest.md): A mechanism that encrypts stored data with managed keys, so the storage medium alone does not reveal it.
- [Encryption in Transit](https://banes-lab.com/records/architecture/encryption-in-transit.md): A mechanism that encrypts traffic between parties with TLS or mutual TLS and verifies the peer's certificate.
- [Secrets Management](https://banes-lab.com/records/architecture/secrets-management.md): The practice of keeping credentials in a secret store, reading them at runtime and rotating them on a schedule.
- [Privacy by Design](https://banes-lab.com/records/architecture/privacy-by-design.md): A design rule that privacy protection is part of a system's design from its first version, covering which personal data it collects, how long it keeps it, who can see it and what its defaults expose.
- [Compliance](https://banes-lab.com/records/architecture/compliance.md): A rule or precondition that a system implements the controls a regulation or standard requires, and keeps evidence of each one.
- [Governance](https://banes-lab.com/records/architecture/governance.md): A design rule that architecture decisions are held to stated policies and standards, through review and automated gates.
- [Policy Enforcement](https://banes-lab.com/records/architecture/policy-enforcement.md): A mechanism that blocks an action a policy forbids at the point the action is attempted.
- [Policy as Code](https://banes-lab.com/records/architecture/policy-as-code.md): A mechanism that expresses policies as machine-readable rules which a pipeline or policy engine evaluates automatically.
- [Risk Management](https://banes-lab.com/records/architecture/risk-management.md): The activity of identifying risks, rating their likelihood and impact, and assigning each one an owner and a mitigation.
- [Continuous Compliance](https://banes-lab.com/records/architecture/continuous-compliance.md): The ability to check compliance on every change, with automated policy gates and evidence capture.
- [CSRF Protection](https://banes-lab.com/records/architecture/csrf-protection.md): A mechanism that rejects state-changing requests which lack proof of coming from the site's own pages, such as an anti-forgery token.
- [Parameterized Queries](https://banes-lab.com/records/architecture/parameterized-queries.md): A mechanism that sends query text and values to the database separately, so values are never parsed as query syntax.
- [Session Management](https://banes-lab.com/records/architecture/session-management.md): A mechanism that keeps authenticated sessions on the server, with expiry, rotation and revocation, and gives the client only an opaque identifier.
