Security Theater

Kind: anti-pattern

Layer: Enforcement Core

Record: architecture:security-theater

Severity: discouraged

Scope: security_governance, model_governance

Formed by: Add visible security controls that do not reduce the actual threat model or can be bypassed by alternate paths.

Canonical: Ontology

A defect in which visible security controls leave the real threat unreduced, or can be bypassed.

Listed in Architecture principles, after Read-Your-Writes Violation and before Authorization Scattering.

Refactored by

Severity

Category

Force

Linked from