# Security / Privacy / Compliance / Governance

> Every principle in this category is listed as a record.

Page: Ontology · Principles
Canonical: https://banes-lab.com/ontology#architecture-category-security-privacy-compliance-governance

Listed in [Ontology · Principles](https://banes-lab.com/api/pages/ontology/principles.md), after [Schema / Canonical Data / Semantics](https://banes-lab.com/ontology/principles/architecture-category-schema-canonical-data-semantics.md) and before [Codebase / System Architecture Styles](https://banes-lab.com/ontology/principles/architecture-category-codebase-system-architecture-styles.md).

Every principle in this category is listed as a record. Each record carries its kind, its severity, the scopes it applies at and the layer it lives in, then the edge relations that join it to other records, the records that point back at it, the contracts that answer to it and the tensions it takes part in. The descriptors say how it is violated, detected, measured, repaired and enforced. Where the record carries one, an exemplar shows the shape before and after the principle is applied.

Relations diagram

The relations inside this category.

```mermaid
flowchart LR
n_security_by_design["Security by Design"]
n_defense_in_depth["Defense in Depth"]
n_least_privilege["Least Privilege"]
n_zero_trust_architecture["Zero Trust Architecture"]
n_secure_by_default["Secure by Default"]
n_attack_surface_reduction["Attack Surface Reduction"]
n_threat_modeling["Threat Modeling"]
n_authentication["Authentication"]
n_authorization["Authorization"]
n_access_control["Access Control"]
n_role_based_access_control["RBAC"]
n_attribute_based_access_control["ABAC"]
n_input_validation["Input Validation"]
n_output_encoding["Output Encoding"]
n_encryption_at_rest["Encryption at Rest"]
n_encryption_in_transit["Encryption in Transit"]
n_secrets_management["Secrets Management"]
n_privacy_by_design["Privacy by Design"]
n_compliance["Compliance"]
n_governance["Governance"]
n_policy_enforcement["Policy Enforcement"]
n_policy_as_code["Policy as Code"]
n_risk_management["Risk Management"]
n_continuous_compliance["Continuous Compliance"]
n_csrf_protection["CSRF Protection"]
n_parameterized_queries["Parameterized Queries"]
n_session_management["Session Management"]
n_security_by_design --> n_threat_modeling
n_security_by_design --> n_secure_by_default
n_security_by_design --> n_defense_in_depth
n_security_by_design --> n_compliance
n_defense_in_depth --> n_security_by_design
n_least_privilege --> n_access_control
n_zero_trust_architecture --> n_least_privilege
n_attack_surface_reduction --> n_security_by_design
n_threat_modeling --> n_security_by_design
n_threat_modeling --> n_risk_management
n_authentication --> n_access_control
n_authorization --> n_least_privilege
n_access_control --> n_least_privilege
n_role_based_access_control --> n_access_control
n_privacy_by_design --> n_compliance
n_compliance --> n_governance
n_compliance --> n_risk_management
n_governance --> n_compliance
n_policy_enforcement --> n_compliance
n_policy_as_code --> n_continuous_compliance
n_risk_management --> n_compliance
n_risk_management --> n_security_by_design
n_continuous_compliance --> n_policy_as_code
n_continuous_compliance --> n_compliance
n_csrf_protection --> n_authentication
n_csrf_protection --> n_defense_in_depth
n_parameterized_queries --> n_input_validation
n_parameterized_queries --> n_secure_by_default
n_session_management --> n_authentication
n_session_management --> n_access_control
n_session_management --> n_least_privilege
```

### Security by Design

- Kind: [principle](https://banes-lab.com/records/kind/principle.md)
- Category: [Security / Privacy / Compliance / Governance](https://banes-lab.com/ontology/principles/architecture-category-security-privacy-compliance-governance.md)
- Severity: [mandatory](https://banes-lab.com/records/vocabulary/severity-mandatory.md)
- Scope: system, service, codebase
- Layer: [Security Core](https://banes-lab.com/records/layer/security-core.md)

Details

Definition
A design rule that threats are modeled and controls built into every component from its first design.

Requires
[Threat Modeling](https://banes-lab.com/records/architecture/threat-modeling.md), [Secure by Default](https://banes-lab.com/records/architecture/secure-by-default.md)

Reinforces
[Defense in Depth](https://banes-lab.com/records/architecture/defense-in-depth.md), [Compliance](https://banes-lab.com/records/architecture/compliance.md)

Enables
[Proactive Risk Reduction](https://banes-lab.com/records/lexicon/proactive-risk-reduction.md)

In tension with
[Developer Ergonomics](https://banes-lab.com/records/lexicon/developer-ergonomics.md)

Conflicts with
[Security as Afterthought](https://banes-lab.com/records/lexicon/security-as-afterthought.md)

Referenced by
[Fail Secure](https://banes-lab.com/records/architecture/fail-secure.md), [Defense in Depth](https://banes-lab.com/records/architecture/defense-in-depth.md), [Attack Surface Reduction](https://banes-lab.com/records/architecture/attack-surface-reduction.md), [Threat Modeling](https://banes-lab.com/records/architecture/threat-modeling.md), [Risk Management](https://banes-lab.com/records/architecture/risk-management.md)

Contracts
[Security Core](https://banes-lab.com/records/algorithms/security-core.md)

Tensions
[Security by Design / Developer Ergonomics](https://banes-lab.com/records/tension/developer-ergonomics-security-by-design.md)

Distinct from
[Attack Surface Reduction](https://banes-lab.com/records/architecture/attack-surface-reduction.md): Security by design builds controls in from the first design, while attack surface reduction removes what nothing uses.

Distinct from
[Fail Secure](https://banes-lab.com/records/architecture/fail-secure.md): Security by design is the approach to every component, while fail secure is one rule, that a failed check denies access.

Distinct from
[Defense in Depth](https://banes-lab.com/records/architecture/defense-in-depth.md): Security by design puts controls in from the start, while defense in depth layers several independent controls on each asset.

Distinct from
[Secure by Default](https://banes-lab.com/records/architecture/secure-by-default.md): Security by design shapes the whole design, while secure by default fixes the state its settings ship in.

Violated by
security controls added only at perimeter

Detected by
missing authz/input validation/threat model

Measured by
security control coverage

Refactored by
Add Security Boundary, Validate Input, Enforce Access

Enforced by
security gates, [policy-as-code](https://banes-lab.com/records/architecture/policy-as-code.md)

Before

```typescript
function createFoo(request: Request) {
return fooStore.save(request.body as Foo);
}
```

After

```typescript
function createFoo(request: Request, identity: Identity) {
const input = CreateFooSchema.parse(request.body);
authorize(identity, "foo:create");
return fooStore.save(Foo.create(input));
}
```

How it is checked

Checked by
security gates, policy-as-code

Population
Every endpoint, credential, data store, permission and policy inside the trust boundary

Freshness
A verdict stands until the code, the policy, the configuration or the threat model changes

Refusal
The security gate, policy engine or secret scan fails the change or rejects the request

Observation
Scans of source and configuration, policy decisions, and security test results

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The policy and the threat model, which code, configuration and requests conform to

Depends on
[Threat Modeling](https://banes-lab.com/records/architecture/threat-modeling.md), [Secure by Default](https://banes-lab.com/records/architecture/secure-by-default.md), [Defense in Depth](https://banes-lab.com/records/architecture/defense-in-depth.md), [Compliance](https://banes-lab.com/records/architecture/compliance.md), [Proactive Risk Reduction](https://banes-lab.com/records/lexicon/proactive-risk-reduction.md)

Shape it refuses
[Security as Afterthought](https://banes-lab.com/records/lexicon/security-as-afterthought.md)

### Defense in Depth

- Kind: [principle](https://banes-lab.com/records/kind/principle.md)
- Category: [Security / Privacy / Compliance / Governance](https://banes-lab.com/ontology/principles/architecture-category-security-privacy-compliance-governance.md)
- Severity: [mandatory](https://banes-lab.com/records/vocabulary/severity-mandatory.md)
- Scope: system, infrastructure, application
- Layer: [Security Core](https://banes-lab.com/records/layer/security-core.md)

Details

Definition
A design rule that several independent security controls protect each asset, so one failed control does not expose it.

Requires
[Layered Controls](https://banes-lab.com/records/lexicon/layered-controls.md)

Reinforces
[Security by Design](https://banes-lab.com/records/architecture/security-by-design.md)

Enables
[Compromise Containment](https://banes-lab.com/records/lexicon/compromise-containment.md)

In tension with
[Complexity](https://banes-lab.com/records/lexicon/complexity.md)

Conflicts with
[Single Control Reliance](https://banes-lab.com/records/lexicon/single-control-reliance.md)

Referenced by
[Security by Design](https://banes-lab.com/records/architecture/security-by-design.md), [CSRF Protection](https://banes-lab.com/records/architecture/csrf-protection.md)

Tensions
[Defense in Depth / Complexity](https://banes-lab.com/records/tension/complexity-defense-in-depth.md)

Violated by
relying on only one security layer

Detected by
missing secondary control

Measured by
control depth

Refactored by
Add Layered Controls

Enforced by
threat model review

Before

```typescript
app.post("/foo", createFoo);
```

After

```typescript
app.post("/foo",
authenticate(),
authorize("foo:create"),
validate(CreateFooSchema),
rateLimit({ limit: 100 }),
audit("FOO_CREATE"),
createFoo,
);
```

How it is checked

Checked by
threat model review

Population
Every endpoint, credential, data store, permission and policy inside the trust boundary

Freshness
A verdict stands until the code, the policy, the configuration or the threat model changes

Refusal
The security gate, policy engine or secret scan fails the change or rejects the request

Observation
Scans of source and configuration, policy decisions, and security test results

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The policy and the threat model, which code, configuration and requests conform to

Depends on
[Layered Controls](https://banes-lab.com/records/lexicon/layered-controls.md), [Security by Design](https://banes-lab.com/records/architecture/security-by-design.md), [Compromise Containment](https://banes-lab.com/records/lexicon/compromise-containment.md)

Shape it refuses
[Single Control Reliance](https://banes-lab.com/records/lexicon/single-control-reliance.md)

### Least Privilege

- Kind: [principle](https://banes-lab.com/records/kind/principle.md)
- Category: [Security / Privacy / Compliance / Governance](https://banes-lab.com/ontology/principles/architecture-category-security-privacy-compliance-governance.md)
- Severity: [mandatory](https://banes-lab.com/records/vocabulary/severity-mandatory.md)
- Scope: user, service, process, data
- Layer: [Security Core](https://banes-lab.com/records/layer/security-core.md)

Details

Definition
A design rule that each user, service and process holds only the permissions its task needs.

Requires
[Access Control](https://banes-lab.com/records/architecture/access-control.md), [Minimal Permissions](https://banes-lab.com/records/lexicon/minimal-permissions.md)

Reinforces
[Zero Trust](https://banes-lab.com/records/lexicon/zero-trust.md), [Damage Limitation](https://banes-lab.com/records/lexicon/damage-limitation.md)

Enables
[Reduced Blast Radius](https://banes-lab.com/records/lexicon/reduced-blast-radius.md)

In tension with
[Operational Convenience](https://banes-lab.com/records/lexicon/operational-convenience.md)

Conflicts with
[Broad Admin Access](https://banes-lab.com/records/lexicon/broad-admin-access.md)

Referenced by
[Zero Trust Architecture](https://banes-lab.com/records/architecture/zero-trust-architecture.md), [Authorization](https://banes-lab.com/records/architecture/authorization.md), [Access Control](https://banes-lab.com/records/architecture/access-control.md), [Session Management](https://banes-lab.com/records/architecture/session-management.md)

Contracts
[Least Privilege Over Broad Privilege](https://banes-lab.com/records/algorithms/no-broad-privilege.md)

Tensions
[Least Privilege / Operational Convenience](https://banes-lab.com/records/tension/least-privilege-operational-convenience.md)

Violated by
excessive permissions

Detected by
overbroad roles/scopes

Measured by
privilege excess count

Refactored by
Narrow Role, Split Permission

Enforced by
IAM policy checks

Before

```typescript
class FooJob {
constructor(private readonly db: AdminDatabase) {}
run(foo: Foo) { return this.db.execute(`insert into foo values (?)`, foo); }
}
```

After

```typescript
interface FooWriter { insert(foo: Foo): Promise<void>; }
class FooJob {
constructor(private readonly foos: FooWriter) {}
run(foo: Foo) { return this.foos.insert(foo); }
}
```

How it is checked

Checked by
IAM policy checks

Population
Every endpoint, credential, data store, permission and policy inside the trust boundary

Freshness
A verdict stands until the code, the policy, the configuration or the threat model changes

Refusal
The security gate, policy engine or secret scan fails the change or rejects the request

Observation
Scans of source and configuration, policy decisions, and security test results

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The policy and the threat model, which code, configuration and requests conform to

Depends on
[Access Control](https://banes-lab.com/records/architecture/access-control.md), [Minimal Permissions](https://banes-lab.com/records/lexicon/minimal-permissions.md), [Zero Trust](https://banes-lab.com/records/lexicon/zero-trust.md), [Damage Limitation](https://banes-lab.com/records/lexicon/damage-limitation.md), [Reduced Blast Radius](https://banes-lab.com/records/lexicon/reduced-blast-radius.md)

Shape it refuses
[Broad Admin Access](https://banes-lab.com/records/lexicon/broad-admin-access.md)

### Zero Trust Architecture

- Kind: [style](https://banes-lab.com/records/kind/style.md)
- Category: [Security / Privacy / Compliance / Governance](https://banes-lab.com/ontology/principles/architecture-category-security-privacy-compliance-governance.md)
- Severity: [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- Scope: system, network, identity
- Layer: [Security Core](https://banes-lab.com/records/layer/security-core.md)

Details

Definition
A convention of authenticating and authorizing every request on its own identity and context, whatever network it comes from.

Requires
[Strong Identity](https://banes-lab.com/records/lexicon/strong-identity.md), [Continuous Authorization](https://banes-lab.com/records/lexicon/continuous-authorization.md)

Reinforces
[Least Privilege](https://banes-lab.com/records/architecture/least-privilege.md)

Enables
[Perimeterless Security](https://banes-lab.com/records/lexicon/perimeterless-security.md)

In tension with
[Latency/Complexity](https://banes-lab.com/records/lexicon/latency-complexity.md)

Conflicts with
[Trusted Internal Network Assumption](https://banes-lab.com/records/lexicon/trusted-internal-network-assumption.md)

Tensions
[Zero Trust Architecture / Latency/Complexity](https://banes-lab.com/records/tension/latency-complexity-zero-trust-architecture.md)

Violated by
implicit trust based on network location

Detected by
internal endpoints without authz/authn

Measured by
trustless control coverage

Refactored by
Add AuthN/AuthZ, Segment Network

Enforced by
[policy-as-code](https://banes-lab.com/records/architecture/policy-as-code.md), gateway rules

Before

```typescript
if (request.network === "internal") return createFoo(request.body);
```

After

```typescript
const identity = authenticate(request.credentials);
authorize(identity, "foo:create", { resource: request.body.id });
verifyDevice(request.deviceAttestation);
return createFoo(CreateFooSchema.parse(request.body));
```

How it is checked

Checked by
policy-as-code, gateway rules

Population
Every endpoint, credential, data store, permission and policy inside the trust boundary

Freshness
A verdict stands until the code, the policy, the configuration or the threat model changes

Refusal
The security gate, policy engine or secret scan fails the change or rejects the request

Observation
Scans of source and configuration, policy decisions, and security test results

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The policy and the threat model, which code, configuration and requests conform to

Depends on
[Strong Identity](https://banes-lab.com/records/lexicon/strong-identity.md), [Continuous Authorization](https://banes-lab.com/records/lexicon/continuous-authorization.md), [Least Privilege](https://banes-lab.com/records/architecture/least-privilege.md), [Perimeterless Security](https://banes-lab.com/records/lexicon/perimeterless-security.md)

Shape it refuses
[Trusted Internal Network Assumption](https://banes-lab.com/records/lexicon/trusted-internal-network-assumption.md)

### Secure by Default

- Kind: [principle](https://banes-lab.com/records/kind/principle.md)
- Category: [Security / Privacy / Compliance / Governance](https://banes-lab.com/ontology/principles/architecture-category-security-privacy-compliance-governance.md)
- Severity: [mandatory](https://banes-lab.com/records/vocabulary/severity-mandatory.md)
- Scope: configuration, API, product
- Aliases: Secure Defaults
- Layer: [Security Core](https://banes-lab.com/records/layer/security-core.md)

Details

Definition
A design rule that every setting ships in its most restrictive safe state, and weakening one requires an explicit opt-in.

Requires
[Safe Defaults](https://banes-lab.com/records/lexicon/safe-defaults.md)

Reinforces
[Fail Secure](https://banes-lab.com/records/architecture/fail-secure.md)

Enables
[Reduced Misconfiguration Risk](https://banes-lab.com/records/lexicon/reduced-misconfiguration-risk.md)

In tension with
[Ease of Initial Use](https://banes-lab.com/records/lexicon/ease-of-initial-use.md)

Conflicts with
[Insecure Defaults](https://banes-lab.com/records/lexicon/insecure-defaults.md)

Referenced by
[Fail Secure](https://banes-lab.com/records/architecture/fail-secure.md), [Security by Design](https://banes-lab.com/records/architecture/security-by-design.md), [Parameterized Queries](https://banes-lab.com/records/architecture/parameterized-queries.md)

Tensions
[Secure by Default / Ease of Initial Use](https://banes-lab.com/records/tension/ease-of-initial-use-secure-by-default.md)

Distinct from
[Fail Secure](https://banes-lab.com/records/architecture/fail-secure.md): Secure by default is the state settings ship in, while fail secure is the state a failed check leaves access in.

Distinct from
[Safe Defaults](https://banes-lab.com/records/lexicon/safe-defaults.md): Secure by default restricts access in the shipped settings, while safe defaults avoid harm in the shipped behavior.

Violated by
default open access, default weak settings

Detected by
insecure default config

Measured by
insecure default count

Refactored by
Change Default to Secure, Require Explicit Opt-In

Enforced by
config policy

Before

```typescript
const fooApi = createApi({ public: true, tls: false, audit: false });
```

After

```typescript
const fooApi = createApi({
public: false,
tls: "required",
authentication: "required",
audit: true,
});
```

How it is checked

Checked by
config policy

Population
Every endpoint, credential, data store, permission and policy inside the trust boundary

Freshness
A verdict stands until the code, the policy, the configuration or the threat model changes

Refusal
The security gate, policy engine or secret scan fails the change or rejects the request

Observation
Scans of source and configuration, policy decisions, and security test results

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The policy and the threat model, which code, configuration and requests conform to

Depends on
[Safe Defaults](https://banes-lab.com/records/lexicon/safe-defaults.md), [Fail Secure](https://banes-lab.com/records/architecture/fail-secure.md), [Reduced Misconfiguration Risk](https://banes-lab.com/records/lexicon/reduced-misconfiguration-risk.md)

Shape it refuses
[Insecure Defaults](https://banes-lab.com/records/lexicon/insecure-defaults.md)

### Attack Surface Reduction

- Kind: [principle](https://banes-lab.com/records/kind/principle.md)
- Category: [Security / Privacy / Compliance / Governance](https://banes-lab.com/ontology/principles/architecture-category-security-privacy-compliance-governance.md)
- Severity: [mandatory](https://banes-lab.com/records/vocabulary/severity-mandatory.md)
- Scope: API, service, infrastructure
- Layer: [Security Core](https://banes-lab.com/records/layer/security-core.md)

Details

Definition
A design rule that endpoints, ports, features and permissions nothing uses are removed or disabled.

Requires
[Minimal Exposure](https://banes-lab.com/records/lexicon/minimal-exposure.md)

Reinforces
[Security by Design](https://banes-lab.com/records/architecture/security-by-design.md)

Enables
[Reduced Exploitability](https://banes-lab.com/records/lexicon/reduced-exploitability.md)

In tension with
[Feature Exposure](https://banes-lab.com/records/lexicon/feature-exposure.md)

Conflicts with
[Unnecessary Public Surface](https://banes-lab.com/records/lexicon/unnecessary-public-surface.md)

Tensions
[Attack Surface Reduction / Feature Exposure](https://banes-lab.com/records/tension/attack-surface-reduction-feature-exposure.md)

Violated by
unused open ports/endpoints/permissions

Detected by
exposed unused routes/services

Measured by
exposed surface count

Refactored by
Remove Endpoint, Restrict Access, Disable Feature

Enforced by
attack surface scanning

Before

```typescript
app.enableDebugConsole();
app.exposeAdminApi();
app.loadAllPlugins();
```

After

```typescript
app.register(fooPublicApi);
app.disable("debug-console");
app.disable("admin-api");
app.loadPlugins(approvedFooPlugins);
```

How it is checked

Checked by
attack surface scanning

Population
Every endpoint, credential, data store, permission and policy inside the trust boundary

Freshness
A verdict stands until the code, the policy, the configuration or the threat model changes

Refusal
The security gate, policy engine or secret scan fails the change or rejects the request

Observation
Scans of source and configuration, policy decisions, and security test results

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The policy and the threat model, which code, configuration and requests conform to

Depends on
[Minimal Exposure](https://banes-lab.com/records/lexicon/minimal-exposure.md), [Security by Design](https://banes-lab.com/records/architecture/security-by-design.md), [Reduced Exploitability](https://banes-lab.com/records/lexicon/reduced-exploitability.md)

Shape it refuses
[Unnecessary Public Surface](https://banes-lab.com/records/lexicon/unnecessary-public-surface.md)

### Threat Modeling

- Kind: [activity](https://banes-lab.com/records/kind/activity.md)
- Category: [Security / Privacy / Compliance / Governance](https://banes-lab.com/ontology/principles/architecture-category-security-privacy-compliance-governance.md)
- Severity: [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- Mandatory for: sensitive systems
- Scope: feature, system, architecture
- Layer: [Security Core](https://banes-lab.com/records/layer/security-core.md)

Details

Definition
The activity of listing a flow's assets, trust boundaries and threats, and choosing a mitigation for each threat.

Requires
[Assets](https://banes-lab.com/records/lexicon/assets.md), [Trust Boundaries](https://banes-lab.com/records/lexicon/trust-boundaries.md), [Threat Scenarios](https://banes-lab.com/records/lexicon/threat-scenarios.md)

Reinforces
[Security by Design](https://banes-lab.com/records/architecture/security-by-design.md), [Risk Management](https://banes-lab.com/records/architecture/risk-management.md)

Enables
[Control Selection](https://banes-lab.com/records/lexicon/control-selection.md)

In tension with
[Delivery Speed](https://banes-lab.com/records/lexicon/delivery-speed.md)

Conflicts with
[Assumption-Driven Security](https://banes-lab.com/records/lexicon/assumption-driven-security.md), [Security Theater](https://banes-lab.com/records/architecture/security-theater.md)

Referenced by
[Security by Design](https://banes-lab.com/records/architecture/security-by-design.md)

Tensions
[Threat Modeling / Delivery Speed](https://banes-lab.com/records/tension/delivery-speed-threat-modeling.md)

Distinct from
[Control Selection](https://banes-lab.com/records/lexicon/control-selection.md): Threat modeling lists the assets, boundaries and threats, while control selection chooses the controls that answer them.

Violated by
security-sensitive change without threat review

Detected by
missing threat model for sensitive flow

Measured by
threat model coverage

Refactored by
Add Threat Model, Add Mitigation

Enforced by
security review gates

Before

```typescript
designFooUpload();
shipFooUpload();
```

After

```typescript
const threats = modelThreats(fooUploadFlow, ["spoofing", "tampering", "repudiation", "disclosure", "denial", "elevation"]);
for (const threat of threats) requireMitigation(threat);
shipFooUpload();
```

How it is checked

Checked by
security review gates

Population
Every endpoint, credential, data store, permission and policy inside the trust boundary

Freshness
A verdict stands until the code, the policy, the configuration or the threat model changes

Refusal
The security gate, policy engine or secret scan fails the change or rejects the request

Observation
Scans of source and configuration, policy decisions, and security test results

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The policy and the threat model, which code, configuration and requests conform to

Depends on
[Assets](https://banes-lab.com/records/lexicon/assets.md), [Trust Boundaries](https://banes-lab.com/records/lexicon/trust-boundaries.md), [Threat Scenarios](https://banes-lab.com/records/lexicon/threat-scenarios.md), [Security by Design](https://banes-lab.com/records/architecture/security-by-design.md), [Risk Management](https://banes-lab.com/records/architecture/risk-management.md), [Control Selection](https://banes-lab.com/records/lexicon/control-selection.md)

Shape it refuses
[Assumption-Driven Security](https://banes-lab.com/records/lexicon/assumption-driven-security.md), [Security Theater](https://banes-lab.com/records/architecture/security-theater.md)

### Authentication

- Kind: [mechanism](https://banes-lab.com/records/kind/mechanism.md)
- Category: [Security / Privacy / Compliance / Governance](https://banes-lab.com/ontology/principles/architecture-category-security-privacy-compliance-governance.md)
- Severity: [mandatory](https://banes-lab.com/records/vocabulary/severity-mandatory.md)
- Scope: user, service, API
- Layer: [Security Core](https://banes-lab.com/records/layer/security-core.md)

Details

Definition
A mechanism that verifies a caller's claimed identity from a credential before any protected action runs.

Requires
[Identity Proof](https://banes-lab.com/records/lexicon/identity-proof.md)

Reinforces
[Access Control](https://banes-lab.com/records/architecture/access-control.md)

Enables
[Identity-Aware Authorization](https://banes-lab.com/records/lexicon/identity-aware-authorization.md)

In tension with
[User Experience](https://banes-lab.com/records/lexicon/user-experience.md)

Conflicts with
[Anonymous Sensitive Access](https://banes-lab.com/records/lexicon/anonymous-sensitive-access.md)

Referenced by
[CSRF Protection](https://banes-lab.com/records/architecture/csrf-protection.md), [Session Management](https://banes-lab.com/records/architecture/session-management.md)

Tensions
[Authentication / User Experience](https://banes-lab.com/records/tension/authentication-user-experience.md)

Distinct from
[Access Control](https://banes-lab.com/records/architecture/access-control.md): Authentication verifies who the caller is, while access control decides what that caller may do.

Distinct from
[CSRF Protection](https://banes-lab.com/records/architecture/csrf-protection.md): Authentication verifies an identity, while CSRF protection verifies that a request came from the site's own pages.

Distinct from
[Session Management](https://banes-lab.com/records/architecture/session-management.md): Authentication verifies a credential once, while session management keeps the result across requests.

Violated by
sensitive action without identity verification

Detected by
unauthenticated protected endpoints

Measured by
auth coverage

Refactored by
Add AuthN Middleware/Provider

Enforced by
route policies, [tests](https://banes-lab.com/records/lexicon/tests.md)

Before

```typescript
const userId = request.headers.get("X-User-ID");
return loadFooFor(userId!);
```

After

```typescript
const credential = requireHeader(request, "Authorization");
const identity = await authenticator.verify(credential);
if (!identity) throw new UnauthorizedError();
return loadFooFor(identity.subject);
```

How it is checked

Checked by
route policies, tests

Population
Every endpoint, credential, data store, permission and policy inside the trust boundary

Freshness
A verdict stands until the code, the policy, the configuration or the threat model changes

Refusal
The security gate, policy engine or secret scan fails the change or rejects the request

Observation
Scans of source and configuration, policy decisions, and security test results

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The policy and the threat model, which code, configuration and requests conform to

Depends on
[Identity Proof](https://banes-lab.com/records/lexicon/identity-proof.md), [Access Control](https://banes-lab.com/records/architecture/access-control.md), [Identity-Aware Authorization](https://banes-lab.com/records/lexicon/identity-aware-authorization.md)

Shape it refuses
[Anonymous Sensitive Access](https://banes-lab.com/records/lexicon/anonymous-sensitive-access.md)

### Authorization

- Kind: [mechanism](https://banes-lab.com/records/kind/mechanism.md)
- Category: [Security / Privacy / Compliance / Governance](https://banes-lab.com/ontology/principles/architecture-category-security-privacy-compliance-governance.md)
- Severity: [mandatory](https://banes-lab.com/records/vocabulary/severity-mandatory.md)
- Scope: API, domain action, data access
- Layer: [Security Core](https://banes-lab.com/records/layer/security-core.md)

Details

Definition
A mechanism that decides, from a policy, whether an authenticated principal may perform an action on a resource.

Requires
[Authenticated Principal](https://banes-lab.com/records/lexicon/authenticated-principal.md), [Policy](https://banes-lab.com/records/lexicon/policy.md)

Reinforces
[Least Privilege](https://banes-lab.com/records/architecture/least-privilege.md)

Enables
[Controlled Access](https://banes-lab.com/records/lexicon/controlled-access.md)

In tension with
[Policy Complexity](https://banes-lab.com/records/lexicon/policy-complexity.md)

Conflicts with
[Authenticated-Equals-Authorized](https://banes-lab.com/records/lexicon/authenticated-equals-authorized.md), [Authorization Scattering](https://banes-lab.com/records/architecture/authorization-scattering.md)

Referenced by
[Proxy Pattern](https://banes-lab.com/records/architecture/proxy-pattern.md)

Tensions
[Authorization / Policy Complexity](https://banes-lab.com/records/tension/authorization-policy-complexity.md)

Distinct from
[Remote Stub](https://banes-lab.com/records/lexicon/remote-stub.md): Authorization decides whether a principal may act, while a remote stub forwards calls to an object in another process.

Violated by
missing permission check

Detected by
protected operation without authz guard

Measured by
authorization coverage

Refactored by
Add Policy Check, Centralize Authorization

Enforced by
security tests, [policy-as-code](https://banes-lab.com/records/architecture/policy-as-code.md)

Before

```typescript
const identity = authenticate(request);
return fooStore.delete(request.params.id);
```

After

```typescript
const identity = authenticate(request);
authorize(identity, "foo:delete", { fooId: request.params.id });
return fooStore.delete(request.params.id);
```

How it is checked

Checked by
security tests, policy-as-code

Population
Every endpoint, credential, data store, permission and policy inside the trust boundary

Freshness
A verdict stands until the code, the policy, the configuration or the threat model changes

Refusal
The security gate, policy engine or secret scan fails the change or rejects the request

Observation
Scans of source and configuration, policy decisions, and security test results

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The policy and the threat model, which code, configuration and requests conform to

Depends on
[Authenticated Principal](https://banes-lab.com/records/lexicon/authenticated-principal.md), [Policy](https://banes-lab.com/records/lexicon/policy.md), [Least Privilege](https://banes-lab.com/records/architecture/least-privilege.md), [Controlled Access](https://banes-lab.com/records/lexicon/controlled-access.md)

Shape it refuses
[Authenticated-Equals-Authorized](https://banes-lab.com/records/lexicon/authenticated-equals-authorized.md), [Authorization Scattering](https://banes-lab.com/records/architecture/authorization-scattering.md)

### Access Control

- Kind: [mechanism](https://banes-lab.com/records/kind/mechanism.md)
- Category: [Security / Privacy / Compliance / Governance](https://banes-lab.com/ontology/principles/architecture-category-security-privacy-compliance-governance.md)
- Severity: [mandatory](https://banes-lab.com/records/vocabulary/severity-mandatory.md)
- Scope: API, data, infrastructure
- Layer: [Security Core](https://banes-lab.com/records/layer/security-core.md)

Details

Definition
A mechanism that evaluates an access policy for each request to a resource and denies the request when the policy does not allow it.

Requires
[Authorization Policy](https://banes-lab.com/records/lexicon/authorization-policy.md)

Reinforces
[Least Privilege](https://banes-lab.com/records/architecture/least-privilege.md)

Enables
[Resource Protection](https://banes-lab.com/records/lexicon/resource-protection.md)

In tension with
[Usability](https://banes-lab.com/records/lexicon/usability.md)

Conflicts with
[Unrestricted Access](https://banes-lab.com/records/lexicon/unrestricted-access.md)

Referenced by
[Centralized Configuration](https://banes-lab.com/records/architecture/centralized-configuration.md), [Least Privilege](https://banes-lab.com/records/architecture/least-privilege.md), [Authentication](https://banes-lab.com/records/architecture/authentication.md), [RBAC](https://banes-lab.com/records/architecture/role-based-access-control.md), [Session Management](https://banes-lab.com/records/architecture/session-management.md)

Tensions
[Access Control / Usability](https://banes-lab.com/records/tension/access-control-usability.md)

Distinct from
[Session Management](https://banes-lab.com/records/architecture/session-management.md): Access control evaluates a policy per request, while session management keeps the authenticated session the request carries.

Distinct from
[Config Store](https://banes-lab.com/records/lexicon/config-store.md): Access control decides who may reach a resource, while a config store is one such resource, holding configuration for many services.

Violated by
broad or missing access controls

Detected by
resource endpoint lacking policy

Measured by
access control coverage

Refactored by
Add ACL/RBAC/ABAC Policy

Enforced by
policy tests

Refused by rules
access-control

Before

```typescript
if (user.role === "admin") return fooStore.findAll();
```

After

```typescript
const decision = accessPolicy.evaluate({
subject: user,
action: "foo:list",
resource: { tenantId: request.tenantId },
});
if (!decision.allowed) throw new ForbiddenError();
return fooStore.findAll(request.tenantId);
```

How it is checked

Checked by
policy tests

Population
Every endpoint, credential, data store, permission and policy inside the trust boundary

Freshness
A verdict stands until the code, the policy, the configuration or the threat model changes

Refusal
The security gate, policy engine or secret scan fails the change or rejects the request

Observation
Scans of source and configuration, policy decisions, and security test results

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The policy and the threat model, which code, configuration and requests conform to

Depends on
[Authorization Policy](https://banes-lab.com/records/lexicon/authorization-policy.md), [Least Privilege](https://banes-lab.com/records/architecture/least-privilege.md), [Resource Protection](https://banes-lab.com/records/lexicon/resource-protection.md)

Shape it refuses
[Unrestricted Access](https://banes-lab.com/records/lexicon/unrestricted-access.md)

### RBAC

- Kind: [model](https://banes-lab.com/records/kind/model.md)
- Category: [Security / Privacy / Compliance / Governance](https://banes-lab.com/ontology/principles/architecture-category-security-privacy-compliance-governance.md)
- Severity: [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- Scope: user, role, resource
- Aliases: Role-Based Access Control
- Layer: [Security Core](https://banes-lab.com/records/layer/security-core.md)

Details

Definition
A conceptual representation of access control, Role-Based Access Control (RBAC), in which permissions attach to roles and users receive roles.

Requires
[Role Definitions](https://banes-lab.com/records/lexicon/role-definitions.md)

Reinforces
[Access Control](https://banes-lab.com/records/architecture/access-control.md)

Enables
[Coarse-Grained Permission Management](https://banes-lab.com/records/lexicon/coarse-grained-permission-management.md)

In tension with
[Role Explosion](https://banes-lab.com/records/lexicon/role-explosion.md)

Conflicts with
[Ad-Hoc Permission Checks](https://banes-lab.com/records/lexicon/ad-hoc-permission-checks.md)

Tensions
[RBAC / Role Explosion](https://banes-lab.com/records/tension/rbac-role-explosion.md)

Violated by
hardcoded user-specific access logic

Detected by
scattered role checks

Measured by
role-policy consistency

Refactored by
Centralize Role Policy

Enforced by
authorization tests

Before

```typescript
if (user.name === "Developer") allowDeleteFoo();
```

After

```typescript
const roles = new Map([
["foo-reader", ["foo:read"]],
["foo-editor", ["foo:read", "foo:write"]],
["foo-admin", ["foo:read", "foo:write", "foo:delete"]],
]);
authorizeRole(user.roles, "foo:delete", roles);
```

How it is checked

Checked by
authorization tests

Population
Every endpoint, credential, data store, permission and policy inside the trust boundary

Freshness
A verdict stands until the code, the policy, the configuration or the threat model changes

Refusal
The security gate, policy engine or secret scan fails the change or rejects the request

Observation
Scans of source and configuration, policy decisions, and security test results

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The policy and the threat model, which code, configuration and requests conform to

Depends on
[Role Definitions](https://banes-lab.com/records/lexicon/role-definitions.md), [Access Control](https://banes-lab.com/records/architecture/access-control.md), [Coarse-Grained Permission Management](https://banes-lab.com/records/lexicon/coarse-grained-permission-management.md)

Shape it refuses
[Ad-Hoc Permission Checks](https://banes-lab.com/records/lexicon/ad-hoc-permission-checks.md)

### ABAC

- Kind: [model](https://banes-lab.com/records/kind/model.md)
- Category: [Security / Privacy / Compliance / Governance](https://banes-lab.com/ontology/principles/architecture-category-security-privacy-compliance-governance.md)
- Severity: [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- Scope: user, resource, context
- Aliases: Attribute-Based Access Control
- Layer: [Security Core](https://banes-lab.com/records/layer/security-core.md)

Details

Definition
A conceptual representation of access control, Attribute-Based Access Control (ABAC), in which a policy decides from attributes of the subject, the resource and the environment.

Requires
[Attribute Definitions](https://banes-lab.com/records/lexicon/attribute-definitions.md), [Policy Engine](https://banes-lab.com/records/lexicon/policy-engine.md)

Reinforces
[Fine-Grained Access Control](https://banes-lab.com/records/lexicon/fine-grained-access-control.md)

Enables
[Context-Aware Authorization](https://banes-lab.com/records/lexicon/context-aware-authorization.md)

In tension with
[Policy Complexity](https://banes-lab.com/records/lexicon/policy-complexity.md)

Conflicts with
[Hardcoded Rules](https://banes-lab.com/records/lexicon/hardcoded-rules.md)

Tensions
[ABAC / Policy Complexity](https://banes-lab.com/records/tension/abac-policy-complexity.md)

Violated by
complex access logic embedded in code

Detected by
duplicated attribute checks in handlers

Measured by
policy centralization

Refactored by
Extract Policy, Add Policy Engine

Enforced by
[policy-as-code](https://banes-lab.com/records/architecture/policy-as-code.md)

Before

```typescript
if (user.role === "editor") return updateFoo(foo);
```

After

```typescript
const decision = policy.evaluate({
subject: { id: user.id, department: user.department },
action: "foo:update",
resource: { ownerId: foo.ownerId, classification: foo.classification },
environment: { time: clock.now() },
});
if (!decision.allowed) throw new ForbiddenError();
```

How it is checked

Checked by
policy-as-code

Population
Every endpoint, credential, data store, permission and policy inside the trust boundary

Freshness
A verdict stands until the code, the policy, the configuration or the threat model changes

Refusal
The security gate, policy engine or secret scan fails the change or rejects the request

Observation
Scans of source and configuration, policy decisions, and security test results

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The policy and the threat model, which code, configuration and requests conform to

Depends on
[Attribute Definitions](https://banes-lab.com/records/lexicon/attribute-definitions.md), [Policy Engine](https://banes-lab.com/records/lexicon/policy-engine.md), [Fine-Grained Access Control](https://banes-lab.com/records/lexicon/fine-grained-access-control.md), [Context-Aware Authorization](https://banes-lab.com/records/lexicon/context-aware-authorization.md)

Shape it refuses
[Hardcoded Rules](https://banes-lab.com/records/lexicon/hardcoded-rules.md)

### Input Validation

- Kind: [mechanism](https://banes-lab.com/records/kind/mechanism.md)
- Category: [Security / Privacy / Compliance / Governance](https://banes-lab.com/ontology/principles/architecture-category-security-privacy-compliance-governance.md)
- Severity: [mandatory](https://banes-lab.com/records/vocabulary/severity-mandatory.md)
- Scope: API, boundary, function
- Layer: [Security Core](https://banes-lab.com/records/layer/security-core.md)

Details

Definition
A mechanism that checks external input against a schema at the boundary before core logic uses it.

Requires
[Validation Rules](https://banes-lab.com/records/lexicon/validation-rules.md), [Schema](https://banes-lab.com/records/lexicon/schema.md)

Reinforces
[Security](https://banes-lab.com/records/lexicon/security.md), [Correctness](https://banes-lab.com/records/architecture/correctness.md)

Enables
[Fail Fast](https://banes-lab.com/records/architecture/fail-fast.md)

In tension with
[Input Flexibility](https://banes-lab.com/records/lexicon/input-flexibility.md)

Conflicts with
[Trusting External Input](https://banes-lab.com/records/lexicon/trusting-external-input.md)

Referenced by
[Preconditions](https://banes-lab.com/records/architecture/preconditions.md), [Defensive Programming](https://banes-lab.com/records/architecture/defensive-programming.md), [Parameterized Queries](https://banes-lab.com/records/architecture/parameterized-queries.md)

Contracts
[Boundary Validation Over Unvalidated Input](https://banes-lab.com/records/algorithms/no-unvalidated-input.md)

Tensions
[Input Validation / Input Flexibility](https://banes-lab.com/records/tension/input-flexibility-input-validation.md)

Violated by
raw external data entering core logic

Detected by
missing boundary validators

Measured by
validation coverage

Refactored by
Add Validator, Add Schema

Enforced by
validation middleware, [tests](https://banes-lab.com/records/lexicon/tests.md)

Refused by rules
input-validation

Before

```typescript
const input = request.body as Foo;
fooStore.save(input);
```

After

```typescript
const input = CreateFooSchema.parse(request.body);
fooStore.save(input);
```

How it is checked

Checked by
validation middleware, tests

Population
Every endpoint, credential, data store, permission and policy inside the trust boundary

Freshness
A verdict stands until the code, the policy, the configuration or the threat model changes

Refusal
The security gate, policy engine or secret scan fails the change or rejects the request

Observation
Scans of source and configuration, policy decisions, and security test results

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The policy and the threat model, which code, configuration and requests conform to

Depends on
[Validation Rules](https://banes-lab.com/records/lexicon/validation-rules.md), [Schema](https://banes-lab.com/records/lexicon/schema.md), [Security](https://banes-lab.com/records/lexicon/security.md), [Correctness](https://banes-lab.com/records/architecture/correctness.md), [Fail Fast](https://banes-lab.com/records/architecture/fail-fast.md)

Shape it refuses
[Trusting External Input](https://banes-lab.com/records/lexicon/trusting-external-input.md)

### Output Encoding

- Kind: [mechanism](https://banes-lab.com/records/kind/mechanism.md)
- Category: [Security / Privacy / Compliance / Governance](https://banes-lab.com/ontology/principles/architecture-category-security-privacy-compliance-governance.md)
- Severity: [mandatory](https://banes-lab.com/records/vocabulary/severity-mandatory.md)
- Scope: UI, API, serialization
- Layer: [Security Core](https://banes-lab.com/records/layer/security-core.md)

Details

Definition
A mechanism that escapes values for the context they are written into, such as HTML, SQL or a shell.

Requires
[Context-Aware Encoding](https://banes-lab.com/records/lexicon/context-aware-encoding.md)

Reinforces
[Injection Prevention](https://banes-lab.com/records/lexicon/injection-prevention.md)

Enables
[Safe Rendering](https://banes-lab.com/records/lexicon/safe-rendering.md)

In tension with
[Formatting Flexibility](https://banes-lab.com/records/lexicon/formatting-flexibility.md)

Conflicts with
[Raw Output Rendering](https://banes-lab.com/records/lexicon/raw-output-rendering.md)

Tensions
[Output Encoding / Formatting Flexibility](https://banes-lab.com/records/tension/formatting-flexibility-output-encoding.md)

Violated by
unescaped user-controlled output

Detected by
raw HTML/SQL/shell output paths

Measured by
unsafe sink count

Refactored by
Encode Output, Use Safe Templates

Enforced by
security linting

Before

```typescript
response.html(`<div>${foo.name}</div>`);
```

After

```typescript
response.html(`<div>${escapeHtml(foo.name)}</div>`);
```

How it is checked

Checked by
security linting

Population
Every endpoint, credential, data store, permission and policy inside the trust boundary

Freshness
A verdict stands until the code, the policy, the configuration or the threat model changes

Refusal
The security gate, policy engine or secret scan fails the change or rejects the request

Observation
Scans of source and configuration, policy decisions, and security test results

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The policy and the threat model, which code, configuration and requests conform to

Depends on
[Context-Aware Encoding](https://banes-lab.com/records/lexicon/context-aware-encoding.md), [Injection Prevention](https://banes-lab.com/records/lexicon/injection-prevention.md), [Safe Rendering](https://banes-lab.com/records/lexicon/safe-rendering.md)

Shape it refuses
[Raw Output Rendering](https://banes-lab.com/records/lexicon/raw-output-rendering.md)

### Encryption at Rest

- Kind: [mechanism](https://banes-lab.com/records/kind/mechanism.md)
- Category: [Security / Privacy / Compliance / Governance](https://banes-lab.com/ontology/principles/architecture-category-security-privacy-compliance-governance.md)
- Severity: [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- Mandatory for: sensitive data
- Scope: storage, database, backups
- Layer: [Security Core](https://banes-lab.com/records/layer/security-core.md)

Details

Definition
A mechanism that encrypts stored data with managed keys, so the storage medium alone does not reveal it.

Requires
[Key Management](https://banes-lab.com/records/lexicon/key-management.md)

Reinforces
[Data Protection](https://banes-lab.com/records/lexicon/data-protection.md)

Enables
[Confidentiality of Stored Data](https://banes-lab.com/records/lexicon/confidentiality-of-stored-data.md)

In tension with
[Key Operations](https://banes-lab.com/records/lexicon/key-operations.md)

Conflicts with
[Plaintext Sensitive Storage](https://banes-lab.com/records/lexicon/plaintext-sensitive-storage.md)

Tensions
[Encryption at Rest / Key Operations](https://banes-lab.com/records/tension/encryption-at-rest-key-operations.md)

Violated by
sensitive data stored unencrypted

Detected by
storage config scan

Measured by
encrypted storage coverage

Refactored by
Enable Encryption, Add KMS

Enforced by
infrastructure policy

Refused by rules
encryption-at-rest

Before

```typescript
await disk.write("foos.json", JSON.stringify(foos));
```

After

```typescript
const ciphertext = await keyManager.encrypt("foo-data-key", JSON.stringify(foos));
await disk.write("foos.enc", ciphertext);
```

How it is checked

Checked by
infrastructure policy

Population
Every endpoint, credential, data store, permission and policy inside the trust boundary

Freshness
A verdict stands until the code, the policy, the configuration or the threat model changes

Refusal
The security gate, policy engine or secret scan fails the change or rejects the request

Observation
Scans of source and configuration, policy decisions, and security test results

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The policy and the threat model, which code, configuration and requests conform to

Depends on
[Key Management](https://banes-lab.com/records/lexicon/key-management.md), [Data Protection](https://banes-lab.com/records/lexicon/data-protection.md), [Confidentiality of Stored Data](https://banes-lab.com/records/lexicon/confidentiality-of-stored-data.md)

Shape it refuses
[Plaintext Sensitive Storage](https://banes-lab.com/records/lexicon/plaintext-sensitive-storage.md)

### Encryption in Transit

- Kind: [mechanism](https://banes-lab.com/records/kind/mechanism.md)
- Category: [Security / Privacy / Compliance / Governance](https://banes-lab.com/ontology/principles/architecture-category-security-privacy-compliance-governance.md)
- Severity: [mandatory](https://banes-lab.com/records/vocabulary/severity-mandatory.md)
- Scope: network, service communication
- Layer: [Security Core](https://banes-lab.com/records/layer/security-core.md)

Details

Definition
A mechanism that encrypts traffic between parties with TLS or mutual TLS and verifies the peer's certificate.

Requires
[TLS/mTLS](https://banes-lab.com/records/lexicon/tls-mtls.md)

Reinforces
[Confidentiality](https://banes-lab.com/records/lexicon/confidentiality.md), [Integrity](https://banes-lab.com/records/lexicon/integrity.md)

Enables
[Secure Communication](https://banes-lab.com/records/lexicon/secure-communication.md)

In tension with
[Certificate Management](https://banes-lab.com/records/lexicon/certificate-management.md)

Conflicts with
[Plaintext Transport](https://banes-lab.com/records/lexicon/plaintext-transport.md)

Tensions
[Encryption in Transit / Certificate Management](https://banes-lab.com/records/tension/certificate-management-encryption-in-transit.md)

Distinct from
[TLS/mTLS](https://banes-lab.com/records/lexicon/tls-mtls.md): Encryption in transit is the practice of encrypting traffic and verifying peers, while TLS and mutual TLS are the protocols that do it.

Violated by
sensitive traffic over plaintext

Detected by
HTTP/plain socket usage

Measured by
encrypted transport coverage

Refactored by
Enable TLS/mTLS

Enforced by
gateway/network policy

Refused by rules
encryption-in-transit

Before

```typescript
const client = new HttpClient("http://foo.internal");
```

After

```typescript
const client = new HttpClient("https://foo.internal", {
tls: { minVersion: "TLSv1.3", verifyPeer: true },
});
```

How it is checked

Checked by
gateway/network policy

Population
Every endpoint, credential, data store, permission and policy inside the trust boundary

Freshness
A verdict stands until the code, the policy, the configuration or the threat model changes

Refusal
The security gate, policy engine or secret scan fails the change or rejects the request

Observation
Scans of source and configuration, policy decisions, and security test results

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The policy and the threat model, which code, configuration and requests conform to

Depends on
[TLS/mTLS](https://banes-lab.com/records/lexicon/tls-mtls.md), [Confidentiality](https://banes-lab.com/records/lexicon/confidentiality.md), [Integrity](https://banes-lab.com/records/lexicon/integrity.md), [Secure Communication](https://banes-lab.com/records/lexicon/secure-communication.md)

Shape it refuses
[Plaintext Transport](https://banes-lab.com/records/lexicon/plaintext-transport.md)

### Secrets Management

- Kind: [activity](https://banes-lab.com/records/kind/activity.md)
- Category: [Security / Privacy / Compliance / Governance](https://banes-lab.com/ontology/principles/architecture-category-security-privacy-compliance-governance.md)
- Severity: [mandatory](https://banes-lab.com/records/vocabulary/severity-mandatory.md)
- Scope: config, deployment, runtime
- Layer: [Security Core](https://banes-lab.com/records/layer/security-core.md)

Details

Definition
The practice of keeping credentials in a secret store, reading them at runtime and rotating them on a schedule.

Requires
[Secret Store](https://banes-lab.com/records/lexicon/secret-store.md), [Rotation Policy](https://banes-lab.com/records/lexicon/rotation-policy.md)

Reinforces
[Secure Configuration](https://banes-lab.com/records/lexicon/secure-configuration.md)

Enables
[Safe Credential Handling](https://banes-lab.com/records/lexicon/safe-credential-handling.md)

In tension with
[Operational Complexity](https://banes-lab.com/records/lexicon/operational-complexity.md)

Conflicts with
[Hardcoded Secrets](https://banes-lab.com/records/lexicon/hardcoded-secrets.md), [Secret Sprawl](https://banes-lab.com/records/architecture/secret-sprawl.md)

Contracts
[Secret Store Over Hardcoded Secrets](https://banes-lab.com/records/algorithms/no-hardcoded-secrets.md)

Tensions
[Secrets Management / Operational Complexity](https://banes-lab.com/records/tension/operational-complexity-secrets-management.md)

Violated by
secrets in code/config files/logs

Detected by
secret scanning

Measured by
secret exposure count

Refactored by
Move to Secret Manager, Rotate Secret

Enforced by
secret scans, CI gates

Before

```typescript
const fooClient = new FooClient({ apiKey: "foo_live_abc123" });
```

After

```typescript
const apiKey = await secretStore.read("services/foo/api-key");
if (!apiKey) throw new Error("missing foo api key");
const fooClient = new FooClient({ apiKey });
```

How it is checked

Checked by
secret scans, CI gates

Population
Every endpoint, credential, data store, permission and policy inside the trust boundary

Freshness
A verdict stands until the code, the policy, the configuration or the threat model changes

Refusal
The security gate, policy engine or secret scan fails the change or rejects the request

Observation
Scans of source and configuration, policy decisions, and security test results

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The policy and the threat model, which code, configuration and requests conform to

Depends on
[Secret Store](https://banes-lab.com/records/lexicon/secret-store.md), [Rotation Policy](https://banes-lab.com/records/lexicon/rotation-policy.md), [Secure Configuration](https://banes-lab.com/records/lexicon/secure-configuration.md), [Safe Credential Handling](https://banes-lab.com/records/lexicon/safe-credential-handling.md)

Shape it refuses
[Hardcoded Secrets](https://banes-lab.com/records/lexicon/hardcoded-secrets.md), [Secret Sprawl](https://banes-lab.com/records/architecture/secret-sprawl.md)

### Privacy by Design

- Kind: [principle](https://banes-lab.com/records/kind/principle.md)
- Category: [Security / Privacy / Compliance / Governance](https://banes-lab.com/ontology/principles/architecture-category-security-privacy-compliance-governance.md)
- Severity: [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- Mandatory for: systems holding personal data
- Scope: data, product, system
- Layer: [Security Core](https://banes-lab.com/records/layer/security-core.md)

Details

Definition
A design rule that privacy protection is part of a system's design from its first version, covering which personal data it collects, how long it keeps it, who can see it and what its defaults expose.

Requires
[Data Minimization](https://banes-lab.com/records/lexicon/data-minimization.md), [Consent/Policy](https://banes-lab.com/records/lexicon/consent-policy.md)

Reinforces
[Compliance](https://banes-lab.com/records/architecture/compliance.md), [Security](https://banes-lab.com/records/lexicon/security.md)

Enables
[Privacy Compliance](https://banes-lab.com/records/lexicon/privacy-compliance.md)

In tension with
[Analytics/Personalization](https://banes-lab.com/records/lexicon/analytics-personalization.md)

Conflicts with
[Personal Data Oversharing](https://banes-lab.com/records/architecture/personal-data-oversharing.md)

Tensions
[Privacy by Design / Analytics/Personalization](https://banes-lab.com/records/tension/analytics-personalization-privacy-by-design.md)

Distinct from
[Data Minimization](https://banes-lab.com/records/lexicon/data-minimization.md): Privacy by design covers collection, retention, visibility and defaults from the first version, while data minimization is its collection and retention part.

Violated by
collecting or retaining unnecessary personal data

Detected by
personal-data flow without policy

Measured by
personal-data surface, retention compliance

Refactored by
Minimize Data, Add Retention/Delete Controls

Enforced by
privacy review, [policy-as-code](https://banes-lab.com/records/architecture/policy-as-code.md)

Before

```typescript
auditLog.append({ user, request, foo, headers: request.headers });
```

After

```typescript
auditLog.append({
actorId: pseudonymize(user.id),
action: "FOO_READ",
fooId: foo.id,
purpose: "support",
});
```

How it is checked

Checked by
privacy review, policy-as-code

Population
Every endpoint, credential, data store, permission and policy inside the trust boundary

Freshness
A verdict stands until the code, the policy, the configuration or the threat model changes

Refusal
The security gate, policy engine or secret scan fails the change or rejects the request

Observation
Scans of source and configuration, policy decisions, and security test results

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The policy and the threat model, which code, configuration and requests conform to

Depends on
[Data Minimization](https://banes-lab.com/records/lexicon/data-minimization.md), [Consent/Policy](https://banes-lab.com/records/lexicon/consent-policy.md), [Compliance](https://banes-lab.com/records/architecture/compliance.md), [Security](https://banes-lab.com/records/lexicon/security.md), [Privacy Compliance](https://banes-lab.com/records/lexicon/privacy-compliance.md)

Shape it refuses
[Personal Data Oversharing](https://banes-lab.com/records/architecture/personal-data-oversharing.md), [Personal Data Oversharing](https://banes-lab.com/records/architecture/personal-data-oversharing.md)

### Compliance

- Kind: [constraint](https://banes-lab.com/records/kind/constraint.md)
- Category: [Security / Privacy / Compliance / Governance](https://banes-lab.com/ontology/principles/architecture-category-security-privacy-compliance-governance.md)
- Severity: [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- Mandatory for: regulated systems
- Scope: system, organization, process
- Layer: [Security Core](https://banes-lab.com/records/layer/security-core.md)

Details

Definition
A rule or precondition that a system implements the controls a regulation or standard requires, and keeps evidence of each one.

Requires
[Controls](https://banes-lab.com/records/lexicon/controls.md), [Evidence](https://banes-lab.com/records/lexicon/evidence.md), [Auditability](https://banes-lab.com/records/architecture/auditability.md)

Reinforces
[Governance](https://banes-lab.com/records/architecture/governance.md), [Risk Management](https://banes-lab.com/records/architecture/risk-management.md)

Enables
[Regulatory Alignment](https://banes-lab.com/records/lexicon/regulatory-alignment.md)

In tension with
[Delivery Speed](https://banes-lab.com/records/lexicon/delivery-speed.md)

Conflicts with
[Uncontrolled Change](https://banes-lab.com/records/lexicon/uncontrolled-change.md)

Referenced by
[Reproducibility](https://banes-lab.com/records/architecture/reproducibility.md), [Standards Compliance](https://banes-lab.com/records/architecture/standards-compliance.md), [Model Governance](https://banes-lab.com/records/architecture/model-governance.md), [Auditability](https://banes-lab.com/records/architecture/auditability.md), [Security by Design](https://banes-lab.com/records/architecture/security-by-design.md), [Privacy by Design](https://banes-lab.com/records/architecture/privacy-by-design.md), [Governance](https://banes-lab.com/records/architecture/governance.md), [Policy Enforcement](https://banes-lab.com/records/architecture/policy-enforcement.md), [Risk Management](https://banes-lab.com/records/architecture/risk-management.md), [Continuous Compliance](https://banes-lab.com/records/architecture/continuous-compliance.md)

Tensions
[Compliance / Delivery Speed](https://banes-lab.com/records/tension/compliance-delivery-speed.md)

Violated by
missing controls/evidence for required regulation

Detected by
compliance gap assessment

Measured by
control pass rate

Refactored by
Add Control, Add Evidence Capture

Enforced by
compliance gates

Before

```typescript
storeFooData(foo);
```

After

```typescript
const classified = classify(foo);
const controls = compliance.requirements(classified, "foo-storage");
await enforceControls(controls);
await storeFooData(foo);
```

How it is checked

Checked by
compliance gates

Population
Every endpoint, credential, data store, permission and policy inside the trust boundary

Freshness
A verdict stands until the code, the policy, the configuration or the threat model changes

Refusal
The security gate, policy engine or secret scan fails the change or rejects the request

Observation
Scans of source and configuration, policy decisions, and security test results

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The policy and the threat model, which code, configuration and requests conform to

Depends on
[Controls](https://banes-lab.com/records/lexicon/controls.md), [Evidence](https://banes-lab.com/records/lexicon/evidence.md), [Auditability](https://banes-lab.com/records/architecture/auditability.md), [Governance](https://banes-lab.com/records/architecture/governance.md), [Risk Management](https://banes-lab.com/records/architecture/risk-management.md), [Regulatory Alignment](https://banes-lab.com/records/lexicon/regulatory-alignment.md)

Shape it refuses
[Uncontrolled Change](https://banes-lab.com/records/lexicon/uncontrolled-change.md)

### Governance

- Kind: [principle](https://banes-lab.com/records/kind/principle.md)
- Category: [Security / Privacy / Compliance / Governance](https://banes-lab.com/ontology/principles/architecture-category-security-privacy-compliance-governance.md)
- Severity: [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- Scope: organization, architecture, platform
- Layer: [Security Core](https://banes-lab.com/records/layer/security-core.md)

Details

Definition
A design rule that architecture decisions are held to stated policies and standards, through review and automated gates.

Requires
[Policy](https://banes-lab.com/records/lexicon/policy.md), [Standards](https://banes-lab.com/records/lexicon/standards.md), [Review](https://banes-lab.com/records/lexicon/review.md)

Reinforces
[Compliance](https://banes-lab.com/records/architecture/compliance.md), [Consistency](https://banes-lab.com/records/architecture/consistency.md)

Enables
[Controlled Evolution](https://banes-lab.com/records/lexicon/controlled-evolution.md)

In tension with
[Team Velocity](https://banes-lab.com/records/lexicon/team-velocity.md)

Conflicts with
[Unbounded Autonomy](https://banes-lab.com/records/lexicon/unbounded-autonomy.md)

Referenced by
[Explicit Boundaries](https://banes-lab.com/records/architecture/explicit-boundaries.md), [Versioning](https://banes-lab.com/records/architecture/versioning.md), [Control Plane](https://banes-lab.com/records/architecture/control-plane.md), [Centralized Configuration](https://banes-lab.com/records/architecture/centralized-configuration.md), [Centralized Authentication](https://banes-lab.com/records/architecture/centralized-authentication.md), [Decentralization](https://banes-lab.com/records/architecture/decentralization.md), [Infrastructure as Code](https://banes-lab.com/records/architecture/infrastructure-as-code.md), [Autonomy](https://banes-lab.com/records/architecture/autonomy.md), [Assessment](https://banes-lab.com/records/architecture/assessment.md), [Gap Analysis](https://banes-lab.com/records/architecture/gap-analysis.md), [Architecture Decision Records (ADR)](https://banes-lab.com/records/architecture/architecture-decision-records.md), [Architectural Consistency](https://banes-lab.com/records/architecture/architectural-consistency.md), [Explainability](https://banes-lab.com/records/architecture/explainability.md), [Single Source of Truth](https://banes-lab.com/records/architecture/single-source-of-truth.md), [Compliance](https://banes-lab.com/records/architecture/compliance.md)

Tensions
[Governance / Team Velocity](https://banes-lab.com/records/tension/governance-team-velocity.md)

Distinct from
[Decentralization](https://banes-lab.com/records/architecture/decentralization.md): Governance holds decisions to shared policy, while decentralization leaves them with the owning teams.

Distinct from
[Standardization](https://banes-lab.com/records/architecture/standardization.md): Governance reviews and gates decisions against policy, while standardization is one policy it can enforce, one choice per concern.

Violated by
unmanaged architecture divergence

Detected by
standard violations, undocumented decisions

Measured by
policy compliance

Refactored by
Add Standards, Add Review Process

Enforced by
architecture board, [policy-as-code](https://banes-lab.com/records/architecture/policy-as-code.md)

Before

```typescript
teams.defineFooApisIndependently();
```

After

```typescript
const governance = defineArchitecturePolicy({
apiVersioning: "required",
schemaRegistry: "required",
ownership: "single-team",
});
architectureGate.enforce(governance);
```

How it is checked

Checked by
architecture board, policy-as-code

Population
Every endpoint, credential, data store, permission and policy inside the trust boundary

Freshness
A verdict stands until the code, the policy, the configuration or the threat model changes

Refusal
The security gate, policy engine or secret scan fails the change or rejects the request

Observation
Scans of source and configuration, policy decisions, and security test results

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The policy and the threat model, which code, configuration and requests conform to

Depends on
[Policy](https://banes-lab.com/records/lexicon/policy.md), [Standards](https://banes-lab.com/records/lexicon/standards.md), [Review](https://banes-lab.com/records/lexicon/review.md), [Compliance](https://banes-lab.com/records/architecture/compliance.md), [Consistency](https://banes-lab.com/records/architecture/consistency.md), [Controlled Evolution](https://banes-lab.com/records/lexicon/controlled-evolution.md)

Shape it refuses
[Unbounded Autonomy](https://banes-lab.com/records/lexicon/unbounded-autonomy.md)

### Policy Enforcement

- Kind: [mechanism](https://banes-lab.com/records/kind/mechanism.md)
- Category: [Security / Privacy / Compliance / Governance](https://banes-lab.com/ontology/principles/architecture-category-security-privacy-compliance-governance.md)
- Severity: [mandatory](https://banes-lab.com/records/vocabulary/severity-mandatory.md)
- Scope: code, infrastructure, runtime
- Layer: [Security Core](https://banes-lab.com/records/layer/security-core.md)

Details

Definition
A mechanism that blocks an action a policy forbids at the point the action is attempted.

Requires
[Defined Policy](https://banes-lab.com/records/lexicon/defined-policy.md)

Reinforces
[Compliance](https://banes-lab.com/records/architecture/compliance.md), [Security](https://banes-lab.com/records/lexicon/security.md)

Enables
[Automated Control](https://banes-lab.com/records/lexicon/automated-control.md)

In tension with
[False Positives](https://banes-lab.com/records/lexicon/false-positives.md)

Conflicts with
[Manual-Only Review](https://banes-lab.com/records/lexicon/manual-only-review.md)

Tensions
[Policy Enforcement / False Positives](https://banes-lab.com/records/tension/false-positives-policy-enforcement.md)

Violated by
unenforced policy

Detected by
policy drift

Measured by
policy violation count

Refactored by
Codify Policy, Add Gate

Enforced by
CI/CD, runtime policy engine

Before

```typescript
if (!policyAllows(user, foo)) fooLog.record("policy violation");
return updateFoo(foo);
```

After

```typescript
if (!policyAllows(user, foo)) throw new ForbiddenError();
return updateFoo(foo);
```

How it is checked

Checked by
CI/CD, runtime policy engine

Population
Every endpoint, credential, data store, permission and policy inside the trust boundary

Freshness
A verdict stands until the code, the policy, the configuration or the threat model changes

Refusal
The security gate, policy engine or secret scan fails the change or rejects the request

Observation
Scans of source and configuration, policy decisions, and security test results

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The policy and the threat model, which code, configuration and requests conform to

Depends on
[Defined Policy](https://banes-lab.com/records/lexicon/defined-policy.md), [Compliance](https://banes-lab.com/records/architecture/compliance.md), [Security](https://banes-lab.com/records/lexicon/security.md), [Automated Control](https://banes-lab.com/records/lexicon/automated-control.md)

Shape it refuses
[Manual-Only Review](https://banes-lab.com/records/lexicon/manual-only-review.md)

### Policy as Code

- Kind: [mechanism](https://banes-lab.com/records/kind/mechanism.md)
- Category: [Security / Privacy / Compliance / Governance](https://banes-lab.com/ontology/principles/architecture-category-security-privacy-compliance-governance.md)
- Severity: [recommended](https://banes-lab.com/records/vocabulary/severity-recommended.md)
- Scope: infrastructure, deployment, security
- Layer: [Security Core](https://banes-lab.com/records/layer/security-core.md)

Details

Definition
A mechanism that expresses policies as machine-readable rules which a pipeline or policy engine evaluates automatically.

Requires
[Machine-Readable Policies](https://banes-lab.com/records/lexicon/machine-readable-policies.md)

Reinforces
[Continuous Compliance](https://banes-lab.com/records/architecture/continuous-compliance.md)

Enables
[Automated Enforcement](https://banes-lab.com/records/lexicon/automated-enforcement.md)

In tension with
[Policy Maintenance](https://banes-lab.com/records/lexicon/policy-maintenance.md)

Conflicts with
[Manual-Only Governance](https://banes-lab.com/records/architecture/manual-only-governance.md)

Referenced by
[Continuous Compliance](https://banes-lab.com/records/architecture/continuous-compliance.md)

Tensions
[Policy as Code / Policy Maintenance](https://banes-lab.com/records/tension/policy-as-code-policy-maintenance.md)

Violated by
manual policy checks not represented in code

Detected by
missing policy rule for known control

Measured by
automated policy coverage

Refactored by
Encode Policy, Add CI Gate

Enforced by
[policy engine](https://banes-lab.com/records/lexicon/policy-engine.md)

Before

```typescript
document.write("Only foo-admin may delete Foo");
```

After

```typescript
const fooDeletePolicy = policy({
action: "foo:delete",
allow: input => input.subject.roles.includes("foo-admin"),
});
policyGate.enforce(fooDeletePolicy);
```

How it is checked

Checked by
policy engine

Population
Every endpoint, credential, data store, permission and policy inside the trust boundary

Freshness
A verdict stands until the code, the policy, the configuration or the threat model changes

Refusal
The security gate, policy engine or secret scan fails the change or rejects the request

Observation
Scans of source and configuration, policy decisions, and security test results

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The policy and the threat model, which code, configuration and requests conform to

Depends on
[Machine-Readable Policies](https://banes-lab.com/records/lexicon/machine-readable-policies.md), [Continuous Compliance](https://banes-lab.com/records/architecture/continuous-compliance.md), [Automated Enforcement](https://banes-lab.com/records/lexicon/automated-enforcement.md)

Shape it refuses
[Manual-Only Governance](https://banes-lab.com/records/architecture/manual-only-governance.md), [Manual-Only Governance](https://banes-lab.com/records/architecture/manual-only-governance.md)

### Risk Management

- Kind: [activity](https://banes-lab.com/records/kind/activity.md)
- Category: [Security / Privacy / Compliance / Governance](https://banes-lab.com/ontology/principles/architecture-category-security-privacy-compliance-governance.md)
- Severity: [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- Scope: architecture, security, delivery
- Layer: [Security Core](https://banes-lab.com/records/layer/security-core.md)

Details

Definition
The activity of identifying risks, rating their likelihood and impact, and assigning each one an owner and a mitigation.

Requires
[Risk Identification](https://banes-lab.com/records/lexicon/risk-identification.md), [Mitigation](https://banes-lab.com/records/lexicon/mitigation.md)

Reinforces
[Compliance](https://banes-lab.com/records/architecture/compliance.md), [Security by Design](https://banes-lab.com/records/architecture/security-by-design.md)

Enables
[Priority-Based Controls](https://banes-lab.com/records/lexicon/priority-based-controls.md)

In tension with
[Speed](https://banes-lab.com/records/lexicon/speed.md)

Conflicts with
[Unowned Risk](https://banes-lab.com/records/architecture/unowned-risk.md)

Referenced by
[Threat Modeling](https://banes-lab.com/records/architecture/threat-modeling.md), [Compliance](https://banes-lab.com/records/architecture/compliance.md)

Tensions
[Risk Management / Speed](https://banes-lab.com/records/tension/risk-management-speed.md)

Distinct from
[Mitigation](https://banes-lab.com/records/lexicon/mitigation.md): Risk management is the whole cycle of identifying, rating and owning risks, while mitigation is the step that reduces one.

Distinct from
[Risk Identification](https://banes-lab.com/records/lexicon/risk-identification.md): Risk management runs the whole cycle, while risk identification is its first step, finding the risks.

Distinct from
[Threat Modeling](https://banes-lab.com/records/architecture/threat-modeling.md): Risk management covers every kind of risk, while threat modeling covers the security threats to one flow.

Violated by
critical risk without owner/mitigation

Detected by
risk register gaps

Measured by
residual risk score

Refactored by
Add Mitigation, Reduce Exposure

Enforced by
review gates

Before

```typescript
shipFooFeature();
```

After

```typescript
const risk = assessRisk(fooFeature, {
likelihood: 3,
impact: 5,
controls: ["rate-limit", "audit", "rollback"],
});
if (risk.residual > riskTolerance) throw new Error("risk not accepted");
shipFooFeature();
```

How it is checked

Checked by
review gates

Population
Every endpoint, credential, data store, permission and policy inside the trust boundary

Freshness
A verdict stands until the code, the policy, the configuration or the threat model changes

Refusal
The security gate, policy engine or secret scan fails the change or rejects the request

Observation
Scans of source and configuration, policy decisions, and security test results

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The policy and the threat model, which code, configuration and requests conform to

Depends on
[Risk Identification](https://banes-lab.com/records/lexicon/risk-identification.md), [Mitigation](https://banes-lab.com/records/lexicon/mitigation.md), [Compliance](https://banes-lab.com/records/architecture/compliance.md), [Security by Design](https://banes-lab.com/records/architecture/security-by-design.md), [Priority-Based Controls](https://banes-lab.com/records/lexicon/priority-based-controls.md)

Shape it refuses
[Unowned Risk](https://banes-lab.com/records/architecture/unowned-risk.md), [Unowned Risk](https://banes-lab.com/records/architecture/unowned-risk.md)

### Continuous Compliance

- Kind: [capability](https://banes-lab.com/records/kind/capability.md)
- Category: [Security / Privacy / Compliance / Governance](https://banes-lab.com/ontology/principles/architecture-category-security-privacy-compliance-governance.md)
- Severity: [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- Scope: CI/CD, infrastructure, codebase
- Layer: [Security Core](https://banes-lab.com/records/layer/security-core.md)

Details

Definition
The ability to check compliance on every change, with automated policy gates and evidence capture.

Requires
[Policy as Code](https://banes-lab.com/records/architecture/policy-as-code.md), [Evidence Automation](https://banes-lab.com/records/lexicon/evidence-automation.md)

Reinforces
[Compliance](https://banes-lab.com/records/architecture/compliance.md), [Auditability](https://banes-lab.com/records/architecture/auditability.md)

Enables
[Ongoing Assurance](https://banes-lab.com/records/lexicon/ongoing-assurance.md)

In tension with
[Pipeline Complexity](https://banes-lab.com/records/lexicon/pipeline-complexity.md)

Conflicts with
[Point-in-Time Audit Only](https://banes-lab.com/records/lexicon/point-in-time-audit-only.md)

Referenced by
[Policy as Code](https://banes-lab.com/records/architecture/policy-as-code.md)

Tensions
[Continuous Compliance / Pipeline Complexity](https://banes-lab.com/records/tension/continuous-compliance-pipeline-complexity.md)

Distinct from
[Evidence Automation](https://banes-lab.com/records/lexicon/evidence-automation.md): Continuous compliance checks every change against policy, while evidence automation collects the proof that the checks ran.

Distinct from
[Ongoing Assurance](https://banes-lab.com/records/lexicon/ongoing-assurance.md): Continuous compliance is checking on every change, while ongoing assurance is being able to show at any time that controls still work.

Violated by
compliance verified only manually/reactively

Detected by
missing automated compliance checks

Measured by
continuous control pass rate

Refactored by
Add Automated Evidence, Add Policy Gates

Enforced by
CI/CD controls

Before

```typescript
runComplianceAuditOncePerYear();
```

After

```typescript
pipeline.on("change", async change => {
const result = await complianceScanner.evaluate(change);
if (!result.compliant) throw new ComplianceGateError(result.violations);
});
```

How it is checked

Checked by
CI/CD controls

Population
Every endpoint, credential, data store, permission and policy inside the trust boundary

Freshness
A verdict stands until the code, the policy, the configuration or the threat model changes

Refusal
The security gate, policy engine or secret scan fails the change or rejects the request

Observation
Scans of source and configuration, policy decisions, and security test results

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The policy and the threat model, which code, configuration and requests conform to

Depends on
[Policy as Code](https://banes-lab.com/records/architecture/policy-as-code.md), [Evidence Automation](https://banes-lab.com/records/lexicon/evidence-automation.md), [Compliance](https://banes-lab.com/records/architecture/compliance.md), [Auditability](https://banes-lab.com/records/architecture/auditability.md), [Ongoing Assurance](https://banes-lab.com/records/lexicon/ongoing-assurance.md)

Shape it refuses
[Point-in-Time Audit Only](https://banes-lab.com/records/lexicon/point-in-time-audit-only.md)

### CSRF Protection

- Kind: [mechanism](https://banes-lab.com/records/kind/mechanism.md)
- Category: [Security / Privacy / Compliance / Governance](https://banes-lab.com/ontology/principles/architecture-category-security-privacy-compliance-governance.md)
- Severity: [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- Mandatory for: public APIs
- Scope: service, web, security
- Aliases: Cross-Site Request Forgery Protection
- Layer: [Security Core](https://banes-lab.com/records/layer/security-core.md)

Details

Definition
A mechanism that rejects state-changing requests which lack proof of coming from the site's own pages, such as an anti-forgery token.

Requires
[Request Origin Verification](https://banes-lab.com/records/lexicon/request-origin-verification.md)

Reinforces
[Authentication](https://banes-lab.com/records/architecture/authentication.md), [Defense in Depth](https://banes-lab.com/records/architecture/defense-in-depth.md)

Enables
[Forged-Request Rejection](https://banes-lab.com/records/lexicon/forged-request-rejection.md)

In tension with
[Client Complexity](https://banes-lab.com/records/lexicon/client-complexity.md)

Conflicts with
[Ambient-Credential Trust](https://banes-lab.com/records/lexicon/ambient-credential-trust.md)

Tensions
[CSRF Protection / Client Complexity](https://banes-lab.com/records/tension/client-complexity-csrf-protection.md)

Violated by
state-changing requests trusted on cookie presence alone

Detected by
no anti-forgery token on mutating endpoints

Measured by
unprotected state-changing endpoint count

Refactored by
Add CSRF Tokens / SameSite Enforcement

Enforced by
security review

Before

```typescript
app.post("/foo/delete", deleteFoo);
```

After

```typescript
app.post("/foo/delete", verifyCsrfToken(), requireSameSite(), deleteFoo);
```

How it is checked

Checked by
security review

Population
Every endpoint, credential, data store, permission and policy inside the trust boundary

Freshness
A verdict stands until the code, the policy, the configuration or the threat model changes

Refusal
The security gate, policy engine or secret scan fails the change or rejects the request

Observation
Scans of source and configuration, policy decisions, and security test results

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The policy and the threat model, which code, configuration and requests conform to

Depends on
[Request Origin Verification](https://banes-lab.com/records/lexicon/request-origin-verification.md), [Authentication](https://banes-lab.com/records/architecture/authentication.md), [Defense in Depth](https://banes-lab.com/records/architecture/defense-in-depth.md), [Forged-Request Rejection](https://banes-lab.com/records/lexicon/forged-request-rejection.md)

Shape it refuses
[Ambient-Credential Trust](https://banes-lab.com/records/lexicon/ambient-credential-trust.md)

### Parameterized Queries

- Kind: [mechanism](https://banes-lab.com/records/kind/mechanism.md)
- Category: [Security / Privacy / Compliance / Governance](https://banes-lab.com/ontology/principles/architecture-category-security-privacy-compliance-governance.md)
- Severity: [mandatory](https://banes-lab.com/records/vocabulary/severity-mandatory.md)
- Scope: service, database, security
- Layer: [Security Core](https://banes-lab.com/records/layer/security-core.md)

Details

Definition
A mechanism that sends query text and values to the database separately, so values are never parsed as query syntax.

Requires
[Query Parameter Binding](https://banes-lab.com/records/lexicon/query-parameter-binding.md)

Reinforces
[Input Validation](https://banes-lab.com/records/architecture/input-validation.md), [Secure by Default](https://banes-lab.com/records/architecture/secure-by-default.md)

Enables
[Injection-Safe Data Access](https://banes-lab.com/records/lexicon/injection-safe-data-access.md)

In tension with
[Dynamic Query Flexibility](https://banes-lab.com/records/lexicon/dynamic-query-flexibility.md)

Conflicts with
[String-Concatenated SQL](https://banes-lab.com/records/lexicon/string-concatenated-sql.md)

Tensions
[Parameterized Queries / Dynamic Query Flexibility](https://banes-lab.com/records/tension/dynamic-query-flexibility-parameterized-queries.md)

Distinct from
[Input Validation](https://banes-lab.com/records/architecture/input-validation.md): Parameterized queries keep values out of query syntax whatever they contain, while input validation checks what values contain before use.

Violated by
SQL assembled by concatenating user input

Detected by
string interpolation into query text

Measured by
concatenated-query count

Refactored by
Use Parameterized Queries

Enforced by
security review

Before

```typescript
db.query(`select * from foos where id = '${id}'`);
```

After

```typescript
db.query("select * from foos where id = $1", [id]);
```

How it is checked

Checked by
security review

Population
Every endpoint, credential, data store, permission and policy inside the trust boundary

Freshness
A verdict stands until the code, the policy, the configuration or the threat model changes

Refusal
The security gate, policy engine or secret scan fails the change or rejects the request

Observation
Scans of source and configuration, policy decisions, and security test results

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The policy and the threat model, which code, configuration and requests conform to

Depends on
[Query Parameter Binding](https://banes-lab.com/records/lexicon/query-parameter-binding.md), [Input Validation](https://banes-lab.com/records/architecture/input-validation.md), [Secure by Default](https://banes-lab.com/records/architecture/secure-by-default.md), [Injection-Safe Data Access](https://banes-lab.com/records/lexicon/injection-safe-data-access.md)

Shape it refuses
[String-Concatenated SQL](https://banes-lab.com/records/lexicon/string-concatenated-sql.md)

### Session Management

- Kind: [mechanism](https://banes-lab.com/records/kind/mechanism.md)
- Category: [Security / Privacy / Compliance / Governance](https://banes-lab.com/ontology/principles/architecture-category-security-privacy-compliance-governance.md)
- Severity: [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- Mandatory for: sensitive systems
- Scope: service, authentication, security
- Layer: [Security Core](https://banes-lab.com/records/layer/security-core.md)

Details

Definition
A mechanism that keeps authenticated sessions on the server, with expiry, rotation and revocation, and gives the client only an opaque identifier.

Requires
[Authentication](https://banes-lab.com/records/architecture/authentication.md)

Reinforces
[Access Control](https://banes-lab.com/records/architecture/access-control.md), [Least Privilege](https://banes-lab.com/records/architecture/least-privilege.md)

Enables
[Bounded Session Lifetime](https://banes-lab.com/records/lexicon/bounded-session-lifetime.md), [Revocable Access](https://banes-lab.com/records/lexicon/revocable-access.md)

In tension with
[User Convenience](https://banes-lab.com/records/lexicon/user-convenience.md)

Conflicts with
[Immortal Client-Trusted Session](https://banes-lab.com/records/lexicon/immortal-client-trusted-session.md)

Tensions
[Session Management / User Convenience](https://banes-lab.com/records/tension/session-management-user-convenience.md)

Violated by
client-supplied identity trusted without server-side session

Detected by
no expiry/rotation/revocation on sessions

Measured by
unbounded-session count

Refactored by
Introduce Server-Side Session Management

Enforced by
security review

Before

```typescript
res.cookie("userId", user.id);
```

After

```typescript
const session = await sessions.create(user.id, { ttlMs: 3_600_000, rotateOnAuth: true });
res.cookie("sid", session.id, { httpOnly: true, secure: true, sameSite: "strict" });
```

How it is checked

Checked by
security review

Population
Every endpoint, credential, data store, permission and policy inside the trust boundary

Freshness
A verdict stands until the code, the policy, the configuration or the threat model changes

Refusal
The security gate, policy engine or secret scan fails the change or rejects the request

Observation
Scans of source and configuration, policy decisions, and security test results

Evidence
None, because the catalog states this check as a class, so a watched run belongs to each system that adopts it

Authoritative side
The policy and the threat model, which code, configuration and requests conform to

Depends on
[Authentication](https://banes-lab.com/records/architecture/authentication.md), [Access Control](https://banes-lab.com/records/architecture/access-control.md), [Least Privilege](https://banes-lab.com/records/architecture/least-privilege.md), [Bounded Session Lifetime](https://banes-lab.com/records/lexicon/bounded-session-lifetime.md), [Revocable Access](https://banes-lab.com/records/lexicon/revocable-access.md)

Shape it refuses
[Immortal Client-Trusted Session](https://banes-lab.com/records/lexicon/immortal-client-trusted-session.md)

## Links to

- [principle](https://banes-lab.com/records/kind/principle.md)
- [mandatory](https://banes-lab.com/records/vocabulary/severity-mandatory.md)
- [Security Core](https://banes-lab.com/records/layer/security-core.md)
- [Threat Modeling](https://banes-lab.com/records/architecture/threat-modeling.md)
- [Secure by Default](https://banes-lab.com/records/architecture/secure-by-default.md)
- [Defense in Depth](https://banes-lab.com/records/architecture/defense-in-depth.md)
- [Compliance](https://banes-lab.com/records/architecture/compliance.md)
- [Proactive Risk Reduction](https://banes-lab.com/records/lexicon/proactive-risk-reduction.md)
- [Developer Ergonomics](https://banes-lab.com/records/lexicon/developer-ergonomics.md)
- [Security as Afterthought](https://banes-lab.com/records/lexicon/security-as-afterthought.md)
- [Fail Secure](https://banes-lab.com/records/architecture/fail-secure.md)
- [Attack Surface Reduction](https://banes-lab.com/records/architecture/attack-surface-reduction.md)
- [Risk Management](https://banes-lab.com/records/architecture/risk-management.md)
- [Security Core](https://banes-lab.com/records/algorithms/security-core.md)
- [Security by Design / Developer Ergonomics](https://banes-lab.com/records/tension/developer-ergonomics-security-by-design.md)
- [Policy as Code](https://banes-lab.com/records/architecture/policy-as-code.md)
- [Layered Controls](https://banes-lab.com/records/lexicon/layered-controls.md)
- [Security by Design](https://banes-lab.com/records/architecture/security-by-design.md)
- [Compromise Containment](https://banes-lab.com/records/lexicon/compromise-containment.md)
- [Complexity](https://banes-lab.com/records/lexicon/complexity.md)
- [Single Control Reliance](https://banes-lab.com/records/lexicon/single-control-reliance.md)
- [CSRF Protection](https://banes-lab.com/records/architecture/csrf-protection.md)
- [Defense in Depth / Complexity](https://banes-lab.com/records/tension/complexity-defense-in-depth.md)
- [Access Control](https://banes-lab.com/records/architecture/access-control.md)
- [Minimal Permissions](https://banes-lab.com/records/lexicon/minimal-permissions.md)
- [Zero Trust](https://banes-lab.com/records/lexicon/zero-trust.md)
- [Damage Limitation](https://banes-lab.com/records/lexicon/damage-limitation.md)
- [Reduced Blast Radius](https://banes-lab.com/records/lexicon/reduced-blast-radius.md)
- [Operational Convenience](https://banes-lab.com/records/lexicon/operational-convenience.md)
- [Broad Admin Access](https://banes-lab.com/records/lexicon/broad-admin-access.md)
- [Zero Trust Architecture](https://banes-lab.com/records/architecture/zero-trust-architecture.md)
- [Authorization](https://banes-lab.com/records/architecture/authorization.md)
- [Session Management](https://banes-lab.com/records/architecture/session-management.md)
- [Least Privilege Over Broad Privilege](https://banes-lab.com/records/algorithms/no-broad-privilege.md)
- [Least Privilege / Operational Convenience](https://banes-lab.com/records/tension/least-privilege-operational-convenience.md)
- [style](https://banes-lab.com/records/kind/style.md)
- [contextual](https://banes-lab.com/records/vocabulary/severity-contextual.md)
- [Strong Identity](https://banes-lab.com/records/lexicon/strong-identity.md)
- [Continuous Authorization](https://banes-lab.com/records/lexicon/continuous-authorization.md)
- [Least Privilege](https://banes-lab.com/records/architecture/least-privilege.md)
- [Perimeterless Security](https://banes-lab.com/records/lexicon/perimeterless-security.md)
- [Latency/Complexity](https://banes-lab.com/records/lexicon/latency-complexity.md)
- [Trusted Internal Network Assumption](https://banes-lab.com/records/lexicon/trusted-internal-network-assumption.md)
- [Zero Trust Architecture / Latency/Complexity](https://banes-lab.com/records/tension/latency-complexity-zero-trust-architecture.md)
- [Safe Defaults](https://banes-lab.com/records/lexicon/safe-defaults.md)
- [Reduced Misconfiguration Risk](https://banes-lab.com/records/lexicon/reduced-misconfiguration-risk.md)
- [Ease of Initial Use](https://banes-lab.com/records/lexicon/ease-of-initial-use.md)
- [Insecure Defaults](https://banes-lab.com/records/lexicon/insecure-defaults.md)
- [Parameterized Queries](https://banes-lab.com/records/architecture/parameterized-queries.md)
- [Secure by Default / Ease of Initial Use](https://banes-lab.com/records/tension/ease-of-initial-use-secure-by-default.md)
- [Minimal Exposure](https://banes-lab.com/records/lexicon/minimal-exposure.md)
- [Reduced Exploitability](https://banes-lab.com/records/lexicon/reduced-exploitability.md)
- [Feature Exposure](https://banes-lab.com/records/lexicon/feature-exposure.md)
- [Unnecessary Public Surface](https://banes-lab.com/records/lexicon/unnecessary-public-surface.md)
- [Attack Surface Reduction / Feature Exposure](https://banes-lab.com/records/tension/attack-surface-reduction-feature-exposure.md)
- [activity](https://banes-lab.com/records/kind/activity.md)
- [Assets](https://banes-lab.com/records/lexicon/assets.md)
- [Trust Boundaries](https://banes-lab.com/records/lexicon/trust-boundaries.md)
- [Threat Scenarios](https://banes-lab.com/records/lexicon/threat-scenarios.md)
- [Control Selection](https://banes-lab.com/records/lexicon/control-selection.md)
- [Delivery Speed](https://banes-lab.com/records/lexicon/delivery-speed.md)
- [Assumption-Driven Security](https://banes-lab.com/records/lexicon/assumption-driven-security.md)
- [Security Theater](https://banes-lab.com/records/architecture/security-theater.md)
- [Threat Modeling / Delivery Speed](https://banes-lab.com/records/tension/delivery-speed-threat-modeling.md)
- [mechanism](https://banes-lab.com/records/kind/mechanism.md)
- [Identity Proof](https://banes-lab.com/records/lexicon/identity-proof.md)
- [Identity-Aware Authorization](https://banes-lab.com/records/lexicon/identity-aware-authorization.md)
- [User Experience](https://banes-lab.com/records/lexicon/user-experience.md)
- [Anonymous Sensitive Access](https://banes-lab.com/records/lexicon/anonymous-sensitive-access.md)
- [Authentication / User Experience](https://banes-lab.com/records/tension/authentication-user-experience.md)
- [Tests](https://banes-lab.com/records/lexicon/tests.md)
- [Authenticated Principal](https://banes-lab.com/records/lexicon/authenticated-principal.md)
- [Policy](https://banes-lab.com/records/lexicon/policy.md)
- [Controlled Access](https://banes-lab.com/records/lexicon/controlled-access.md)
- [Policy Complexity](https://banes-lab.com/records/lexicon/policy-complexity.md)
- [Authenticated-Equals-Authorized](https://banes-lab.com/records/lexicon/authenticated-equals-authorized.md)
- [Authorization Scattering](https://banes-lab.com/records/architecture/authorization-scattering.md)
- [Proxy Pattern](https://banes-lab.com/records/architecture/proxy-pattern.md)
- [Authorization / Policy Complexity](https://banes-lab.com/records/tension/authorization-policy-complexity.md)
- [Remote Stub](https://banes-lab.com/records/lexicon/remote-stub.md)
- [Authorization Policy](https://banes-lab.com/records/lexicon/authorization-policy.md)
- [Resource Protection](https://banes-lab.com/records/lexicon/resource-protection.md)
- [Usability](https://banes-lab.com/records/lexicon/usability.md)
- [Unrestricted Access](https://banes-lab.com/records/lexicon/unrestricted-access.md)
- [Centralized Configuration](https://banes-lab.com/records/architecture/centralized-configuration.md)
- [Authentication](https://banes-lab.com/records/architecture/authentication.md)
- [RBAC](https://banes-lab.com/records/architecture/role-based-access-control.md)
- [Access Control / Usability](https://banes-lab.com/records/tension/access-control-usability.md)
- [Config Store](https://banes-lab.com/records/lexicon/config-store.md)
- [model](https://banes-lab.com/records/kind/model.md)
- [Role Definitions](https://banes-lab.com/records/lexicon/role-definitions.md)
- [Coarse-Grained Permission Management](https://banes-lab.com/records/lexicon/coarse-grained-permission-management.md)
- [Role Explosion](https://banes-lab.com/records/lexicon/role-explosion.md)
- [Ad-Hoc Permission Checks](https://banes-lab.com/records/lexicon/ad-hoc-permission-checks.md)
- [RBAC / Role Explosion](https://banes-lab.com/records/tension/rbac-role-explosion.md)
- [Attribute Definitions](https://banes-lab.com/records/lexicon/attribute-definitions.md)
- [Policy Engine](https://banes-lab.com/records/lexicon/policy-engine.md)
- [Fine-Grained Access Control](https://banes-lab.com/records/lexicon/fine-grained-access-control.md)
- [Context-Aware Authorization](https://banes-lab.com/records/lexicon/context-aware-authorization.md)
- [Hardcoded Rules](https://banes-lab.com/records/lexicon/hardcoded-rules.md)
- [ABAC / Policy Complexity](https://banes-lab.com/records/tension/abac-policy-complexity.md)
- [Validation Rules](https://banes-lab.com/records/lexicon/validation-rules.md)
- [Schema](https://banes-lab.com/records/lexicon/schema.md)
- [Security](https://banes-lab.com/records/lexicon/security.md)
- [Correctness](https://banes-lab.com/records/architecture/correctness.md)
- [Fail Fast](https://banes-lab.com/records/architecture/fail-fast.md)
- [Input Flexibility](https://banes-lab.com/records/lexicon/input-flexibility.md)
- [Trusting External Input](https://banes-lab.com/records/lexicon/trusting-external-input.md)
- [Preconditions](https://banes-lab.com/records/architecture/preconditions.md)
- [Defensive Programming](https://banes-lab.com/records/architecture/defensive-programming.md)
- [Boundary Validation Over Unvalidated Input](https://banes-lab.com/records/algorithms/no-unvalidated-input.md)
- [Input Validation / Input Flexibility](https://banes-lab.com/records/tension/input-flexibility-input-validation.md)
- [Context-Aware Encoding](https://banes-lab.com/records/lexicon/context-aware-encoding.md)
- [Injection Prevention](https://banes-lab.com/records/lexicon/injection-prevention.md)
- [Safe Rendering](https://banes-lab.com/records/lexicon/safe-rendering.md)
- [Formatting Flexibility](https://banes-lab.com/records/lexicon/formatting-flexibility.md)
- [Raw Output Rendering](https://banes-lab.com/records/lexicon/raw-output-rendering.md)
- [Output Encoding / Formatting Flexibility](https://banes-lab.com/records/tension/formatting-flexibility-output-encoding.md)
- [Key Management](https://banes-lab.com/records/lexicon/key-management.md)
- [Data Protection](https://banes-lab.com/records/lexicon/data-protection.md)
- [Confidentiality of Stored Data](https://banes-lab.com/records/lexicon/confidentiality-of-stored-data.md)
- [Key Operations](https://banes-lab.com/records/lexicon/key-operations.md)
- [Plaintext Sensitive Storage](https://banes-lab.com/records/lexicon/plaintext-sensitive-storage.md)
- [Encryption at Rest / Key Operations](https://banes-lab.com/records/tension/encryption-at-rest-key-operations.md)
- [TLS/mTLS](https://banes-lab.com/records/lexicon/tls-mtls.md)
- [Confidentiality](https://banes-lab.com/records/lexicon/confidentiality.md)
- [Integrity](https://banes-lab.com/records/lexicon/integrity.md)
- [Secure Communication](https://banes-lab.com/records/lexicon/secure-communication.md)
- [Certificate Management](https://banes-lab.com/records/lexicon/certificate-management.md)
- [Plaintext Transport](https://banes-lab.com/records/lexicon/plaintext-transport.md)
- [Encryption in Transit / Certificate Management](https://banes-lab.com/records/tension/certificate-management-encryption-in-transit.md)
- [Secret Store](https://banes-lab.com/records/lexicon/secret-store.md)
- [Rotation Policy](https://banes-lab.com/records/lexicon/rotation-policy.md)
- [Secure Configuration](https://banes-lab.com/records/lexicon/secure-configuration.md)
- [Safe Credential Handling](https://banes-lab.com/records/lexicon/safe-credential-handling.md)
- [Operational Complexity](https://banes-lab.com/records/lexicon/operational-complexity.md)
- [Hardcoded Secrets](https://banes-lab.com/records/lexicon/hardcoded-secrets.md)
- [Secret Sprawl](https://banes-lab.com/records/architecture/secret-sprawl.md)
- [Secret Store Over Hardcoded Secrets](https://banes-lab.com/records/algorithms/no-hardcoded-secrets.md)
- [Secrets Management / Operational Complexity](https://banes-lab.com/records/tension/operational-complexity-secrets-management.md)
- [Data Minimization](https://banes-lab.com/records/lexicon/data-minimization.md)
- [Consent/Policy](https://banes-lab.com/records/lexicon/consent-policy.md)
- [Privacy Compliance](https://banes-lab.com/records/lexicon/privacy-compliance.md)
- [Analytics/Personalization](https://banes-lab.com/records/lexicon/analytics-personalization.md)
- [Personal Data Oversharing](https://banes-lab.com/records/architecture/personal-data-oversharing.md)
- [Privacy by Design / Analytics/Personalization](https://banes-lab.com/records/tension/analytics-personalization-privacy-by-design.md)
- [constraint](https://banes-lab.com/records/kind/constraint.md)
- [Controls](https://banes-lab.com/records/lexicon/controls.md)
- [Evidence](https://banes-lab.com/records/lexicon/evidence.md)
- [Auditability](https://banes-lab.com/records/architecture/auditability.md)
- [Governance](https://banes-lab.com/records/architecture/governance.md)
- [Regulatory Alignment](https://banes-lab.com/records/lexicon/regulatory-alignment.md)
- [Uncontrolled Change](https://banes-lab.com/records/lexicon/uncontrolled-change.md)
- [Reproducibility](https://banes-lab.com/records/architecture/reproducibility.md)
- [Standards Compliance](https://banes-lab.com/records/architecture/standards-compliance.md)
- [Model Governance](https://banes-lab.com/records/architecture/model-governance.md)
- [Privacy by Design](https://banes-lab.com/records/architecture/privacy-by-design.md)
- [Policy Enforcement](https://banes-lab.com/records/architecture/policy-enforcement.md)
- [Continuous Compliance](https://banes-lab.com/records/architecture/continuous-compliance.md)
- [Compliance / Delivery Speed](https://banes-lab.com/records/tension/compliance-delivery-speed.md)
- [Standards](https://banes-lab.com/records/lexicon/standards.md)
- [Review](https://banes-lab.com/records/lexicon/review.md)
- [Consistency](https://banes-lab.com/records/architecture/consistency.md)
- [Controlled Evolution](https://banes-lab.com/records/lexicon/controlled-evolution.md)
- [Team Velocity](https://banes-lab.com/records/lexicon/team-velocity.md)
- [Unbounded Autonomy](https://banes-lab.com/records/lexicon/unbounded-autonomy.md)
- [Explicit Boundaries](https://banes-lab.com/records/architecture/explicit-boundaries.md)
- [Versioning](https://banes-lab.com/records/architecture/versioning.md)
- [Control Plane](https://banes-lab.com/records/architecture/control-plane.md)
- [Centralized Authentication](https://banes-lab.com/records/architecture/centralized-authentication.md)
- [Decentralization](https://banes-lab.com/records/architecture/decentralization.md)
- [Infrastructure as Code](https://banes-lab.com/records/architecture/infrastructure-as-code.md)
- [Autonomy](https://banes-lab.com/records/architecture/autonomy.md)
- [Assessment](https://banes-lab.com/records/architecture/assessment.md)
- [Gap Analysis](https://banes-lab.com/records/architecture/gap-analysis.md)
- [Architecture Decision Records](https://banes-lab.com/records/architecture/architecture-decision-records.md)
- [Architectural Consistency](https://banes-lab.com/records/architecture/architectural-consistency.md)
- [Explainability](https://banes-lab.com/records/architecture/explainability.md)
- [Single Source of Truth](https://banes-lab.com/records/architecture/single-source-of-truth.md)
- [Governance / Team Velocity](https://banes-lab.com/records/tension/governance-team-velocity.md)
- [Standardization](https://banes-lab.com/records/architecture/standardization.md)
- [Defined Policy](https://banes-lab.com/records/lexicon/defined-policy.md)
- [Automated Control](https://banes-lab.com/records/lexicon/automated-control.md)
- [False Positives](https://banes-lab.com/records/lexicon/false-positives.md)
- [Manual-Only Review](https://banes-lab.com/records/lexicon/manual-only-review.md)
- [Policy Enforcement / False Positives](https://banes-lab.com/records/tension/false-positives-policy-enforcement.md)
- [recommended](https://banes-lab.com/records/vocabulary/severity-recommended.md)
- [Machine-Readable Policies](https://banes-lab.com/records/lexicon/machine-readable-policies.md)
- [Automated Enforcement](https://banes-lab.com/records/lexicon/automated-enforcement.md)
- [Policy Maintenance](https://banes-lab.com/records/lexicon/policy-maintenance.md)
- [Manual-Only Governance](https://banes-lab.com/records/architecture/manual-only-governance.md)
- [Policy as Code / Policy Maintenance](https://banes-lab.com/records/tension/policy-as-code-policy-maintenance.md)
- [Risk Identification](https://banes-lab.com/records/lexicon/risk-identification.md)
- [Mitigation](https://banes-lab.com/records/lexicon/mitigation.md)
- [Priority-Based Controls](https://banes-lab.com/records/lexicon/priority-based-controls.md)
- [Speed](https://banes-lab.com/records/lexicon/speed.md)
- [Unowned Risk](https://banes-lab.com/records/architecture/unowned-risk.md)
- [Risk Management / Speed](https://banes-lab.com/records/tension/risk-management-speed.md)
- [capability](https://banes-lab.com/records/kind/capability.md)
- [Evidence Automation](https://banes-lab.com/records/lexicon/evidence-automation.md)
- [Ongoing Assurance](https://banes-lab.com/records/lexicon/ongoing-assurance.md)
- [Pipeline Complexity](https://banes-lab.com/records/lexicon/pipeline-complexity.md)
- [Point-in-Time Audit Only](https://banes-lab.com/records/lexicon/point-in-time-audit-only.md)
- [Continuous Compliance / Pipeline Complexity](https://banes-lab.com/records/tension/continuous-compliance-pipeline-complexity.md)
- [Request Origin Verification](https://banes-lab.com/records/lexicon/request-origin-verification.md)
- [Forged-Request Rejection](https://banes-lab.com/records/lexicon/forged-request-rejection.md)
- [Client Complexity](https://banes-lab.com/records/lexicon/client-complexity.md)
- [Ambient-Credential Trust](https://banes-lab.com/records/lexicon/ambient-credential-trust.md)
- [CSRF Protection / Client Complexity](https://banes-lab.com/records/tension/client-complexity-csrf-protection.md)
- [Query Parameter Binding](https://banes-lab.com/records/lexicon/query-parameter-binding.md)
- [Input Validation](https://banes-lab.com/records/architecture/input-validation.md)
- [Injection-Safe Data Access](https://banes-lab.com/records/lexicon/injection-safe-data-access.md)
- [Dynamic Query Flexibility](https://banes-lab.com/records/lexicon/dynamic-query-flexibility.md)
- [String-Concatenated SQL](https://banes-lab.com/records/lexicon/string-concatenated-sql.md)
- [Parameterized Queries / Dynamic Query Flexibility](https://banes-lab.com/records/tension/dynamic-query-flexibility-parameterized-queries.md)
- [Bounded Session Lifetime](https://banes-lab.com/records/lexicon/bounded-session-lifetime.md)
- [Revocable Access](https://banes-lab.com/records/lexicon/revocable-access.md)
- [User Convenience](https://banes-lab.com/records/lexicon/user-convenience.md)
- [Immortal Client-Trusted Session](https://banes-lab.com/records/lexicon/immortal-client-trusted-session.md)
- [Session Management / User Convenience](https://banes-lab.com/records/tension/session-management-user-convenience.md)

## Linked from

- [The layer topology](https://banes-lab.com/ontology/schema/the-layer-topology.md)
- [The membership](https://banes-lab.com/ontology/schema/the-membership.md)
