Security / Privacy / Compliance / Governance

Kind: category

Record: architecture-category:security-privacy-compliance-governance

Canonical: Ontology

The Security / Privacy / Compliance / Governance category holds 27 architecture principles.

Listed in Principle categories, after Schema / Canonical Data / Semantics and before Codebase / System Architecture Styles.

Principle

Layer

Linked from

Security / Privacy / Compliance / Governance

Every principle in this category is listed as a record. Each record carries its kind, its severity, the scopes it applies at and the layer it lives in, then the edge relations that join it to other records, the records that point back at it, the contracts that answer to it and the tensions it takes part in. The descriptors say how it is violated, detected, measured, repaired and enforced. Where the record carries one, an exemplar shows the shape before and after the principle is applied.

Relations diagram
The relations inside this category.
flowchart LR
    n_security_by_design["Security by Design"]
    n_defense_in_depth["Defense in Depth"]
    n_least_privilege["Least Privilege"]
    n_zero_trust_architecture["Zero Trust Architecture"]
    n_secure_by_default["Secure by Default"]
    n_attack_surface_reduction["Attack Surface Reduction"]
    n_threat_modeling["Threat Modeling"]
    n_authentication["Authentication"]
    n_authorization["Authorization"]
    n_access_control["Access Control"]
    n_role_based_access_control["Role-Based Access Control (RBAC)"]
    n_attribute_based_access_control["Attribute-Based Access Control (ABAC)"]
    n_input_validation["Input Validation"]
    n_output_encoding["Output Encoding"]
    n_encryption_at_rest["Encryption at Rest"]
    n_encryption_in_transit["Encryption in Transit"]
    n_secrets_management["Secrets Management"]
    n_privacy_by_design["Privacy by Design"]
    n_compliance["Compliance"]
    n_governance["Governance"]
    n_policy_enforcement["Policy Enforcement"]
    n_policy_as_code["Policy as Code"]
    n_risk_management["Risk Management"]
    n_continuous_compliance["Continuous Compliance"]
    n_csrf_protection["CSRF Protection"]
    n_parameterized_queries["Parameterized Queries"]
    n_session_management["Session Management"]
    n_security_by_design --> n_threat_modeling
    n_security_by_design --> n_secure_by_default
    n_security_by_design --> n_defense_in_depth
    n_security_by_design --> n_compliance
    n_defense_in_depth --> n_security_by_design
    n_least_privilege --> n_access_control
    n_least_privilege --> n_zero_trust_architecture
    n_zero_trust_architecture --> n_least_privilege
    n_attack_surface_reduction --> n_security_by_design
    n_threat_modeling --> n_security_by_design
    n_threat_modeling --> n_risk_management
    n_authentication --> n_access_control
    n_authorization --> n_least_privilege
    n_access_control --> n_least_privilege
    n_role_based_access_control --> n_access_control
    n_privacy_by_design --> n_compliance
    n_compliance --> n_governance
    n_compliance --> n_risk_management
    n_governance --> n_compliance
    n_policy_enforcement --> n_compliance
    n_policy_as_code --> n_continuous_compliance
    n_risk_management --> n_compliance
    n_risk_management --> n_security_by_design
    n_continuous_compliance --> n_policy_as_code
    n_continuous_compliance --> n_compliance
    n_csrf_protection --> n_authentication
    n_csrf_protection --> n_defense_in_depth
    n_parameterized_queries --> n_input_validation
    n_parameterized_queries --> n_secure_by_default
    n_session_management --> n_authentication
    n_session_management --> n_access_control
    n_session_management --> n_least_privilege