Security / Privacy / Compliance / Governance
Kind: category
Record: architecture-category:security-privacy-compliance-governance
Canonical: Ontology
The Security / Privacy / Compliance / Governance category holds 27 architecture principles.
Listed in Principle categories, after Schema / Canonical Data / Semantics and before Codebase / System Architecture Styles.
Principle
- Security by Design
- Defense in Depth
- Least Privilege
- Zero Trust Architecture
- Secure by Default
- Attack Surface Reduction
- Threat Modeling
- Authentication
- Authorization
- Access Control
- Role-Based Access Control (RBAC)
- Attribute-Based Access Control (ABAC)
- Input Validation
- Output Encoding
- Encryption at Rest
- Encryption in Transit
- Secrets Management
- Privacy by Design
- Compliance
- Governance
- Policy Enforcement
- Policy as Code
- Risk Management
- Continuous Compliance
- CSRF Protection
- Parameterized Queries
- Session Management
Layer
Linked from
Security / Privacy / Compliance / Governance
Every principle in this category is listed as a record. Each record carries its kind, its severity, the scopes it applies at and the layer it lives in, then the edge relations that join it to other records, the records that point back at it, the contracts that answer to it and the tensions it takes part in. The descriptors say how it is violated, detected, measured, repaired and enforced. Where the record carries one, an exemplar shows the shape before and after the principle is applied.
Relations diagram
flowchart LR
n_security_by_design["Security by Design"]
n_defense_in_depth["Defense in Depth"]
n_least_privilege["Least Privilege"]
n_zero_trust_architecture["Zero Trust Architecture"]
n_secure_by_default["Secure by Default"]
n_attack_surface_reduction["Attack Surface Reduction"]
n_threat_modeling["Threat Modeling"]
n_authentication["Authentication"]
n_authorization["Authorization"]
n_access_control["Access Control"]
n_role_based_access_control["Role-Based Access Control (RBAC)"]
n_attribute_based_access_control["Attribute-Based Access Control (ABAC)"]
n_input_validation["Input Validation"]
n_output_encoding["Output Encoding"]
n_encryption_at_rest["Encryption at Rest"]
n_encryption_in_transit["Encryption in Transit"]
n_secrets_management["Secrets Management"]
n_privacy_by_design["Privacy by Design"]
n_compliance["Compliance"]
n_governance["Governance"]
n_policy_enforcement["Policy Enforcement"]
n_policy_as_code["Policy as Code"]
n_risk_management["Risk Management"]
n_continuous_compliance["Continuous Compliance"]
n_csrf_protection["CSRF Protection"]
n_parameterized_queries["Parameterized Queries"]
n_session_management["Session Management"]
n_security_by_design --> n_threat_modeling
n_security_by_design --> n_secure_by_default
n_security_by_design --> n_defense_in_depth
n_security_by_design --> n_compliance
n_defense_in_depth --> n_security_by_design
n_least_privilege --> n_access_control
n_least_privilege --> n_zero_trust_architecture
n_zero_trust_architecture --> n_least_privilege
n_attack_surface_reduction --> n_security_by_design
n_threat_modeling --> n_security_by_design
n_threat_modeling --> n_risk_management
n_authentication --> n_access_control
n_authorization --> n_least_privilege
n_access_control --> n_least_privilege
n_role_based_access_control --> n_access_control
n_privacy_by_design --> n_compliance
n_compliance --> n_governance
n_compliance --> n_risk_management
n_governance --> n_compliance
n_policy_enforcement --> n_compliance
n_policy_as_code --> n_continuous_compliance
n_risk_management --> n_compliance
n_risk_management --> n_security_by_design
n_continuous_compliance --> n_policy_as_code
n_continuous_compliance --> n_compliance
n_csrf_protection --> n_authentication
n_csrf_protection --> n_defense_in_depth
n_parameterized_queries --> n_input_validation
n_parameterized_queries --> n_secure_by_default
n_session_management --> n_authentication
n_session_management --> n_access_control
n_session_management --> n_least_privilegeSecurity by Design
- Kind: principle
- Category: Security / Privacy / Compliance / Governance
- Severity: mandatory
- Scope: system, service, codebase
- Layer: Security Core
Defense in Depth
- Kind: principle
- Category: Security / Privacy / Compliance / Governance
- Severity: mandatory
- Scope: system, infrastructure, application
- Layer: Security Core
Least Privilege
- Kind: principle
- Category: Security / Privacy / Compliance / Governance
- Severity: mandatory
- Scope: user, service, process, data
- Aliases: Principle of Least Privilege, PoLP
- Layer: Security Core
Zero Trust Architecture
- Kind: style
- Category: Security / Privacy / Compliance / Governance
- Severity: contextual
- Scope: system, network, identity
- Aliases: Zero Trust
- Layer: Security Core
Secure by Default
- Kind: principle
- Category: Security / Privacy / Compliance / Governance
- Severity: mandatory
- Scope: configuration, API, product
- Aliases: Secure Defaults
- Layer: Security Core
Attack Surface Reduction
- Kind: principle
- Category: Security / Privacy / Compliance / Governance
- Severity: mandatory
- Scope: API, service, infrastructure
- Layer: Security Core
Threat Modeling
- Kind: activity
- Category: Security / Privacy / Compliance / Governance
- Severity: contextual
- Mandatory for: sensitive systems
- Scope: feature, system, architecture
- Layer: Security Core
Authentication
- Kind: mechanism
- Category: Security / Privacy / Compliance / Governance
- Severity: mandatory
- Scope: user, service, API
- Layer: Security Core
Authorization
- Kind: mechanism
- Category: Security / Privacy / Compliance / Governance
- Severity: mandatory
- Scope: API, domain action, data access
- Layer: Security Core
Access Control
- Kind: mechanism
- Category: Security / Privacy / Compliance / Governance
- Severity: mandatory
- Scope: API, data, infrastructure
- Layer: Security Core
Role-Based Access Control (RBAC)
- Kind: model
- Category: Security / Privacy / Compliance / Governance
- Severity: contextual
- Scope: user, role, resource
- Aliases: RBAC
- Layer: Security Core
Attribute-Based Access Control (ABAC)
- Kind: model
- Category: Security / Privacy / Compliance / Governance
- Severity: contextual
- Scope: user, resource, context
- Aliases: ABAC
- Layer: Security Core
Input Validation
- Kind: mechanism
- Category: Security / Privacy / Compliance / Governance
- Severity: mandatory
- Scope: API, boundary, function
- Layer: Security Core
Output Encoding
- Kind: mechanism
- Category: Security / Privacy / Compliance / Governance
- Severity: mandatory
- Scope: UI, API, serialization
- Layer: Security Core
Encryption at Rest
- Kind: mechanism
- Category: Security / Privacy / Compliance / Governance
- Severity: contextual
- Mandatory for: sensitive data
- Scope: storage, database, backups
- Layer: Security Core
Encryption in Transit
- Kind: mechanism
- Category: Security / Privacy / Compliance / Governance
- Severity: mandatory
- Scope: network, service communication
- Layer: Security Core
Secrets Management
- Kind: activity
- Category: Security / Privacy / Compliance / Governance
- Severity: mandatory
- Scope: config, deployment, runtime
- Layer: Security Core
Privacy by Design
- Kind: principle
- Category: Security / Privacy / Compliance / Governance
- Severity: contextual
- Mandatory for: systems holding personal data
- Scope: data, product, system
- Layer: Security Core
Compliance
- Kind: constraint
- Category: Security / Privacy / Compliance / Governance
- Severity: contextual
- Mandatory for: regulated systems
- Scope: system, organization, process
- Layer: Security Core
Governance
- Kind: principle
- Category: Security / Privacy / Compliance / Governance
- Severity: contextual
- Scope: organization, architecture, platform
- Layer: Security Core
Policy Enforcement
- Kind: mechanism
- Category: Security / Privacy / Compliance / Governance
- Severity: mandatory
- Scope: code, infrastructure, runtime
- Layer: Security Core
Policy as Code
- Kind: mechanism
- Category: Security / Privacy / Compliance / Governance
- Severity: recommended
- Scope: infrastructure, deployment, security
- Layer: Security Core
Risk Management
- Kind: activity
- Category: Security / Privacy / Compliance / Governance
- Severity: contextual
- Scope: architecture, security, delivery
- Layer: Security Core
Continuous Compliance
- Kind: capability
- Category: Security / Privacy / Compliance / Governance
- Severity: contextual
- Scope: CI/CD, infrastructure, codebase
- Layer: Security Core
CSRF Protection
- Kind: mechanism
- Category: Security / Privacy / Compliance / Governance
- Severity: contextual
- Mandatory for: public APIs
- Scope: service, web, security
- Aliases: Cross-Site Request Forgery Protection
- Layer: Security Core
Parameterized Queries
- Kind: mechanism
- Category: Security / Privacy / Compliance / Governance
- Severity: mandatory
- Scope: service, database, security
- Layer: Security Core
Session Management
- Kind: mechanism
- Category: Security / Privacy / Compliance / Governance
- Severity: contextual
- Mandatory for: sensitive systems
- Scope: service, authentication, security
- Layer: Security Core