Compliance Frameworks
SOC 2, ISO 27001, PCI DSS — scope as an architectural lever.
5 to work through
-
intermediate
A global employment platform passes its compliance audits and is repeatedly found to have real security weaknesses. What is the gap?
2 min answer -
intermediate
A payments dataset must stay in the EU. The team reads that as one EU region and pins all storage there across two availability zones. Six months later the business asks for a 15-minute recovery time objective against a regional failure. What did residency actually cost and when did the bill arrive?
2 min answer -
intermediate
A vendor platform must satisfy security certification requirements while serving customers across many jurisdictions. How should compliance influence architecture without paralysing it?
2 min answer -
advanced
How would you reduce PCI DSS scope for an e-commerce platform, and what does it cost you?
2 min answer -
advanced
PCI DSS assessment covers 40 systems and costs a fortune annually. How would you reduce that architecturally?
2 min answer
2 terms in this topic
Compliance Frameworks
Externally defined control sets — SOC 2, ISO 27001, PCI DSS and others — whose architectural impact is scope, evidence and segmentation.
practiceContinuous Compliance
Producing compliance evidence automatically and continuously from the systems themselves, rather than reconstructing it before an audit.
1 artifact you would hand over
Neighbouring topics
Security Architecture
General material on securing an architecture.
Authentication
Establishing who a principal is, and how strong that claim needs to be.
Authorization
RBAC, ABAC and ReBAC, and centralising the decision but not the enforcement.
OAuth 2.0 & OIDC
Delegated authorisation, and the identity layer that makes login safe.
Tokens & JWTs
Stateless validation, revocation, and pinning the algorithm.
Identity & Access Management
Workload identity, roles, permission boundaries and usage-based review.
Secrets Management
Runtime injection, dynamic credentials and rotation applications survive.
Encryption
At rest, in transit, and at the application layer — three different threats.
Key Management
Rotation, separation of duty, envelope encryption and crypto-shredding.
Zero Trust
No implicit trust from network position; authorise every request.
Threat Modelling
Walking trust boundaries with STRIDE before anything is built.
OWASP Risks
The recurring web and API risk classes, several of which are design flaws.
Secure API Design
Object-level authorisation, input validation and safe error responses.
Supply Chain Security
Dependencies, SBOMs, build provenance and artefact signing.
Network Security
Segmentation, egress control and limiting lateral movement.
Auditability
Tamper-evident, attributed records that survive async boundaries.
Privacy Engineering
Minimisation, purpose limitation, and erasure that is implementable.
Data Classification
Knowing which fields are regulated, because every control depends on it.
Security Incident Response
Detection, scoping, containment and notification clocks.