Security Theater
Kind: anti-pattern
Layer: Enforcement Core
Record: architecture:security-theater
Severity: discouraged
Scope: security_governance, model_governance
Formed by: Add visible security controls that do not reduce the actual threat model or can be bypassed by alternate paths.
Canonical: Ontology
A defect in which visible security controls leave the real threat unreduced, or can be bypassed.
Listed in Architecture principles, after Read-Your-Writes Violation and before Authorization Scattering.