Security Architecture

General material on securing an architecture.

4Questions
18Flashcards
15Terms
Terminology

15 terms in this topic

concept

Auditability

The ability to reconstruct who did what, to which resource, when, and from where — reliably enough to be relied upon after the fact.

concept

Authentication

Establishing who a principal is, to a defined level of confidence.

concept

Authorization

Deciding whether an authenticated principal may perform a specific action on a specific resource.

practice

Compliance Framework

A published set of control requirements an organisation is assessed against, which turns security posture into evidence somebody else will check.

practice

Encryption at Rest and in Transit

Protecting stored data from disclosure if the medium is obtained, and network data from disclosure if the path is observed — two different controls a…

concept

Identity and Access Management

The system of record for principals, credentials and permissions, and the policy engine that decides what each principal may do.

protocol

JSON Web Token

A signed, self-contained token carrying claims, which a service can validate locally without calling the issuer.

concept

Least Privilege

Granting each identity only the permissions it needs, for only as long as it needs them.

protocol

OAuth 2.0

An authorisation framework that lets an application obtain scoped, delegated access to a resource without handling the user's credentials.

protocol

OpenID Connect

An identity layer over OAuth 2.0 that adds a signed ID token asserting who the user is and how they authenticated.

practice

OWASP Top Ten

A periodically updated consensus list of the most critical web application security risks, useful as a design-review checklist.

concept

Personally Identifiable Information

Data relating to an identifiable person — a category far broader than name and address, and the trigger for most regulatory obligation.

practice

Secrets Management

Storing, distributing, rotating and auditing credentials so that they never live in code, images or configuration files.

practice

Threat Modelling

A structured exercise that identifies what can go wrong with a design, before it is built, by walking the system's trust boundaries.

concept

Zero Trust

A security model that grants no implicit trust from network position, and authenticates and authorises every request individually.

Security Architecture

Neighbouring topics

Authentication

Establishing who a principal is, and how strong that claim needs to be.

4 quiz 5 cards 3 terms

Authorization

RBAC, ABAC and ReBAC, and centralising the decision but not the enforcement.

5 quiz 8 cards 6 terms

OAuth 2.0 & OIDC

Delegated authorisation, and the identity layer that makes login safe.

2 quiz 4 cards 3 terms

Tokens & JWTs

Stateless validation, revocation, and pinning the algorithm.

6 quiz 9 cards 5 terms

Identity & Access Management

Workload identity, roles, permission boundaries and usage-based review.

4 quiz 8 cards 5 terms

Secrets Management

Runtime injection, dynamic credentials and rotation applications survive.

5 quiz 8 cards 4 terms

Encryption

At rest, in transit, and at the application layer — three different threats.

4 quiz 9 cards 2 terms

Key Management

Rotation, separation of duty, envelope encryption and crypto-shredding.

4 quiz 7 cards 5 terms

Zero Trust

No implicit trust from network position; authorise every request.

6 quiz 8 cards 3 terms

Threat Modelling

Walking trust boundaries with STRIDE before anything is built.

5 quiz 8 cards 3 terms

OWASP Risks

The recurring web and API risk classes, several of which are design flaws.

2 quiz 7 cards 2 terms

Secure API Design

Object-level authorisation, input validation and safe error responses.

5 quiz 10 cards 2 terms

Supply Chain Security

Dependencies, SBOMs, build provenance and artefact signing.

6 quiz 10 cards 8 terms

Network Security

Segmentation, egress control and limiting lateral movement.

3 quiz 5 cards 3 terms

Auditability

Tamper-evident, attributed records that survive async boundaries.

4 quiz 5 cards 3 terms

Compliance Frameworks

SOC 2, ISO 27001, PCI DSS — scope as an architectural lever.

4 quiz 9 cards 2 terms

Privacy Engineering

Minimisation, purpose limitation, and erasure that is implementable.

3 quiz 8 cards 2 terms

Data Classification

Knowing which fields are regulated, because every control depends on it.

4 quiz 6 cards 2 terms

Security Incident Response

Detection, scoping, containment and notification clocks.

5 quiz 11 cards 3 terms