The security decision
In a possible later extension, a training provider could send a cancellation case to a partner. The partner would need enough information to offer another course. Sending the whole learner record would also expose details the partner does not need. The architecture must decide what may be shared, who can act, and how mistakes are detected and corrected.
Security architecture connects possible harm to the safeguards in the service. It considers people, working practices, information, software, suppliers and physical facilities. Security is an original aspect of A Simple Architectural Framework (ASAF), spanning business and technology. It helps an architect follow a risk through the other aspects and across the life of the service.
What needs protecting
| Concern | Architectural question |
|---|---|
| Confidentiality | Who may see a learner’s details, including copies, exports, support records and summaries? |
| Integrity | Who may change an agreement or accept responsibility, and how are unauthorised changes prevented or detected? |
| Availability | What work can continue during disruption, and who restores a trustworthy service? |
| Accountability | Can an authorised reviewer establish who acted, under which authority, and what happened? |
| Privacy | Which personal information is needed, for what purpose, for how long, and with what consequences for the person? |
Privacy also concerns unnecessary or inappropriate use of information by an authorised party. Access controls contribute to its treatment alongside purpose, minimisation, retention and handling arrangements.
From harm to a control
Start with an asset or business activity and a plausible harmful event. A threat may exploit a weakness: for example, a compromised partner account could expose every learner if its permissions are too broad. Record the risk owner, affected people, assumptions and consequences. Then select controls and explain which part of the risk each control addresses.
Some controls prevent an action; others detect it, limit its effects or help recovery. Allocate each to a person, process or component, with a way to check it. Record the remaining risk and who can accept it. A reviewer’s approval should identify the scope and conditions of acceptance.
For managed services, include what the provider controls and what your team must configure and operate. For a mobile device, include stored copies and actions awaiting acceptance. For a model that summarises a case, include the facts sent to it, retained outputs and the authority of any tools it can call.
Connected responsibilities
Business architecture helps owners relate protection needs to the service’s purpose and the people affected. Information develops permitted use and disclosure. Process covers access changes and support activities; Structure identifies the roles and authority behind them. Systems implements checks where an action takes effect. Technology covers environments, credentials, patching and recovery. Security specialists help assess threats and whether the controls address them. The accountable owner decides whether the remaining risk is acceptable. Deployment and operations brings these controls into service acceptance, daily support and incident response.
The Zero Trust page develops access decisions. The comparison places them alongside broader security methods and practices.
Speed and quality
Measure time to resolve a security decision, waiting for review, rework caused by late constraints and effort spent maintaining controls. Examine the resulting service separately: unauthorised actions, excessive access, disruption, detection and recovery. Include the burden on legitimate users. An absence of reported incidents is weak evidence if detection is ineffective.
Data governance connects access and protection to permitted uses, accountable owners, retention and affected copies.
Methodology configuration
Your method may use risk registers, threat models, assurance cases or security designs. Relate their contents and owners to the decisions here. Use Methodology configuration to map terms, records and reviews to your own approach.