# Architecture principles whose scope is security_governance

> 8 records

This index as JSON: https://banes-lab.com/json/api/facets/architecture/scope/security-governance

## Entries

- [Schema Drift](https://banes-lab.com/records/architecture/schema-drift.md): A defect in which the producers, consumers and stores of one payload evolve its shape independently until its meaning diverges.
- [Manual-Only Governance](https://banes-lab.com/records/architecture/manual-only-governance.md): A defect in which architecture rules or security policies exist only in documents or in reviewers' memory, with no executable check, so they drift from what the system does.
- [Fat Controller](https://banes-lab.com/records/architecture/fat-controller.md): A defect in which controllers hold validation, business rules, persistence and response formatting.
- [Cache Poisoning by Design](https://banes-lab.com/records/architecture/cache-poisoning-by-design.md): A defect in which a cache key omits an input the entry depends on, so one request is served another's result.
- [Security Theater](https://banes-lab.com/records/architecture/security-theater.md): A defect in which visible security controls leave the real threat unreduced, or can be bypassed.
- [Authorization Scattering](https://banes-lab.com/records/architecture/authorization-scattering.md): A defect in which authorization checks are spread across layers with no central policy.
- [Secret Sprawl](https://banes-lab.com/records/architecture/secret-sprawl.md): A defect in which credentials and keys are stored across code, logs and configuration.
- [Feature-Only Design](https://banes-lab.com/records/architecture/feature-only-design.md): A defect in which architecture serves immediate features while its quality attributes go unaddressed.
