Term Kind Topic What it is
Build Provenance Attestation, SLSA Provenance, Artefact Lineage pattern Supply Chain Security A signed, verifiable record of which source, builder and inputs produced a given artefact, checked at deployment - which makes the integrity of the build system testable rather than assumed.
Dynamic Secrets pattern Secrets Management Credentials generated on demand for a specific consumer with a short lease, rather than stored, shared and rotated periodically.
Envelope Encryption pattern Key Management Encrypting data with a locally generated data key, then encrypting that key with a master key held in a key management service.
Field-Level Encryption Application-Level Encryption pattern Encryption Encrypting specific sensitive fields in the application before they reach the datastore, so the store never holds plaintext.
Microsegmentation pattern Zero Trust Enforcing fine-grained network policy between individual workloads rather than between broad network zones, so a compromise cannot move laterally.
Per-Record Tenancy Record-Level Ownership, Attribute-Based Tenancy, Cross-Org Data Ownership pattern Authorization Attaching the owning organisation to each record rather than to its container, so that data shared across tenant boundaries can still be governed, exported, retained and deleted according to the policy of whoe…
Phishing-Resistant Authentication Origin-Bound Authentication, Unphishable MFA pattern Authentication Authentication whose response cannot be replayed at a site other than the one it was produced for, because the authenticator signs the requesting origin rather than releasing a secret the user could pass on.
Policy Decision Point PDP, Authorization Service, Policy Engine pattern Zero Trust The component that evaluates an authorisation question and returns a decision, kept separate from the enforcement points that ask, so policy can change without redeploying every service.
Signing Boundary Policy Policy at the HSM, Constrained Signing pattern Key Management Enforcing transaction policy at the hardware signing boundary rather than in application code, so that a compromised application cannot obtain an arbitrary signature.
Step-Up Authentication pattern Authentication Requiring stronger proof of identity at the moment a consequential action is attempted, rather than applying maximum friction to every session.
Tag-Bound Access Policy Classification-Driven Access Control, Tag-Based Masking pattern Data Classification An access rule attached to a classification label rather than to a table, so that tagging data is what applies the control and derived copies inherit it through lineage.
Tamper-Evident Log pattern Auditability An audit log constructed so that any modification or deletion of past entries is detectable, typically by chaining entries cryptographically.