Authorization

RBAC, ABAC and ReBAC, and centralising the decision but not the enforcement.

5Questions
8Flashcards
6Terms
Security Architecture

Neighbouring topics

Security Architecture

General material on securing an architecture.

4 quiz 18 cards 15 terms

Authentication

Establishing who a principal is, and how strong that claim needs to be.

4 quiz 5 cards 3 terms

OAuth 2.0 & OIDC

Delegated authorisation, and the identity layer that makes login safe.

2 quiz 4 cards 3 terms

Tokens & JWTs

Stateless validation, revocation, and pinning the algorithm.

6 quiz 9 cards 5 terms

Identity & Access Management

Workload identity, roles, permission boundaries and usage-based review.

4 quiz 8 cards 5 terms

Secrets Management

Runtime injection, dynamic credentials and rotation applications survive.

5 quiz 8 cards 4 terms

Encryption

At rest, in transit, and at the application layer — three different threats.

4 quiz 9 cards 2 terms

Key Management

Rotation, separation of duty, envelope encryption and crypto-shredding.

4 quiz 7 cards 5 terms

Zero Trust

No implicit trust from network position; authorise every request.

6 quiz 8 cards 3 terms

Threat Modelling

Walking trust boundaries with STRIDE before anything is built.

5 quiz 8 cards 3 terms

OWASP Risks

The recurring web and API risk classes, several of which are design flaws.

2 quiz 7 cards 2 terms

Secure API Design

Object-level authorisation, input validation and safe error responses.

5 quiz 10 cards 2 terms

Supply Chain Security

Dependencies, SBOMs, build provenance and artefact signing.

6 quiz 10 cards 8 terms

Network Security

Segmentation, egress control and limiting lateral movement.

3 quiz 5 cards 3 terms

Auditability

Tamper-evident, attributed records that survive async boundaries.

4 quiz 5 cards 3 terms

Compliance Frameworks

SOC 2, ISO 27001, PCI DSS — scope as an architectural lever.

4 quiz 9 cards 2 terms

Privacy Engineering

Minimisation, purpose limitation, and erasure that is implementable.

3 quiz 8 cards 2 terms

Data Classification

Knowing which fields are regulated, because every control depends on it.

4 quiz 6 cards 2 terms

Security Incident Response

Detection, scoping, containment and notification clocks.

5 quiz 11 cards 3 terms