Auditability
Tamper-evident, attributed records that survive async boundaries.
4 to work through
-
advanced
A regulated brokerage must prove after the fact who did what, to which account, and on whose authority. What must the architecture provide?
2 min answer -
advanced
A travel platform must be able to answer, months later, who changed a booking and what they saw. What does that require architecturally, and why is a log table insufficient?
2 min answer -
advanced
Design the audit logging for a system handling financial transactions. What is logged, where does it go, and what makes it hold up?
2 min answer -
advanced
Your audit logs are stored in a platform administered by the same team that has production access. What is the problem?
2 min answer
3 terms in this topic
Insider Risk by Design
Designing so that a legitimate operator cannot silently exceed their remit, treating the trusted internal user as part of the threat model.
patternTamper-Evident Log
An audit log constructed so that any modification or deletion of past entries is detectable, typically by chaining entries cryptographically.
practiceTransactional Audit Emission
Writing the audit record in the same transaction as the state change it describes, so that a crash cannot produce a change with no record - the prope…
Neighbouring topics
Security Architecture
General material on securing an architecture.
Authentication
Establishing who a principal is, and how strong that claim needs to be.
Authorization
RBAC, ABAC and ReBAC, and centralising the decision but not the enforcement.
OAuth 2.0 & OIDC
Delegated authorisation, and the identity layer that makes login safe.
Tokens & JWTs
Stateless validation, revocation, and pinning the algorithm.
Identity & Access Management
Workload identity, roles, permission boundaries and usage-based review.
Secrets Management
Runtime injection, dynamic credentials and rotation applications survive.
Encryption
At rest, in transit, and at the application layer — three different threats.
Key Management
Rotation, separation of duty, envelope encryption and crypto-shredding.
Zero Trust
No implicit trust from network position; authorise every request.
Threat Modelling
Walking trust boundaries with STRIDE before anything is built.
OWASP Risks
The recurring web and API risk classes, several of which are design flaws.
Secure API Design
Object-level authorisation, input validation and safe error responses.
Supply Chain Security
Dependencies, SBOMs, build provenance and artefact signing.
Network Security
Segmentation, egress control and limiting lateral movement.
Compliance Frameworks
SOC 2, ISO 27001, PCI DSS — scope as an architectural lever.
Privacy Engineering
Minimisation, purpose limitation, and erasure that is implementable.
Data Classification
Knowing which fields are regulated, because every control depends on it.
Security Incident Response
Detection, scoping, containment and notification clocks.