# Architecture principles whose scope is security

> 10 records

This index as JSON: https://banes-lab.com/json/api/facets/architecture/scope/security

## Entries

- [Standards Compliance](https://banes-lab.com/records/architecture/standards-compliance.md): A rule or precondition that an implementation conforms to the published standard for its protocol, format or domain.
- [Fail Safe](https://banes-lab.com/records/architecture/fail-safe.md): A design rule that a failing operation leaves the system in the state that causes the least harm.
- [Auditability](https://banes-lab.com/records/architecture/auditability.md): The degree to which each sensitive action can be traced afterwards to its actor, target, time and reason.
- [Audit Logging](https://banes-lab.com/records/architecture/audit-logging.md): A mechanism that appends an immutable record of each sensitive operation, naming the actor, the action, the target and the time.
- [Canonicalization](https://banes-lab.com/records/architecture/canonicalization.md): A technique for converting equivalent values to one normal form before they are compared, stored or checked.
- [Policy as Code](https://banes-lab.com/records/architecture/policy-as-code.md): A mechanism that expresses policies as machine-readable rules which a pipeline or policy engine evaluates automatically.
- [Risk Management](https://banes-lab.com/records/architecture/risk-management.md): The activity of identifying risks, rating their likelihood and impact, and assigning each one an owner and a mitigation.
- [CSRF Protection](https://banes-lab.com/records/architecture/csrf-protection.md): A mechanism that rejects state-changing requests which lack proof of coming from the site's own pages, such as an anti-forgery token.
- [Parameterized Queries](https://banes-lab.com/records/architecture/parameterized-queries.md): A mechanism that sends query text and values to the database separately, so values are never parsed as query syntax.
- [Session Management](https://banes-lab.com/records/architecture/session-management.md): A mechanism that keeps authenticated sessions on the server, with expiry, rotation and revocation, and gives the client only an opaque identifier.
