Architecture Portal

Security cycles

Risk decisions through delivery and use.

Adrian Sutherland · Version 1.0 · · © 2005–2026

What reopens a decision

Sharing cancellation cases with a new partner changes who receives personal information. It reopens the disclosure and access decisions even if the software release is small. A routine patch may leave those decisions intact while requiring compatibility and security checks.

ASAF process area Work and accepted result Feedback
Visioning Business and risk owners agree protection needs, direction and tolerable exposure. New services, obligations, threats or unacceptable harm.
Transforming Teams select and implement controls, check them and prepare support. A test failure, dependency or migration exposes an unsafe assumption.
Operating Owners maintain access, observe controls, handle incidents and restore service. Suspicious activity, failed recovery, stale access or changes in use.
Governing Accountable owners review policies, assurance, exceptions and remaining risks. An exception expires, assurance is insufficient or the service changes.

Visioning, Transforming, Operating and Governing are continuing process areas in A Simple Architectural Framework (ASAF). Their activities can overlap. Retain accepted risks, policies and control versions so each iteration can identify what changed and which checks need repeating. Faster generation of code or prompts can produce more candidates; the team still needs to know who may approve their use and effects.

Methodology configuration

Your risk review, release review and incident review may share participants and records. Map the decisions rather than requiring three separate meetings. Use Methodology configuration to map terms, records and reviews to your own approach.

Dials

Dial Choice to examine
Cadence Access reviews on role changes, with periodic reconciliation for missed events.
Batch size One partner’s handover process before broader sharing.
Coordination Risk, information, service and supplier owners join decisions affecting them.
Decision authority Teams change controls within agreed policy; risk acceptance goes to the accountable owner.
Automation and checking Repeatable access tests and configuration checks, with owners assessing the possible business harm.
Learning reach Correct one permission locally; reopen shared policy when the same fault recurs.

Frequent checks take time and effort to maintain, but may uncover problems sooner. Compare the actual waiting, rework and failures with the risk being addressed. For each passed check, retain its inputs, configuration and result.

Diagram

Security decision cycles

Decisions retained through change and use.

Security decision cyclesDecisions retained through change and use. The full nodes and connections are described below the diagram.directionreconsideraccepted changeimprovementprioritieschange authoritypolicyfindingsVisioningTransformingOperatingGoverning
  • Visioning

    Business and risk owners agree protection needs, direction and tolerable exposure.

  • Transforming

    Teams select and implement controls, check them and prepare support.

  • Operating

    Owners maintain access, observe controls, handle incidents and restore service.

  • Governing

    Accountable owners review policies, assurance, exceptions and remaining risks.

Read the connections
  • VisioningTransforming: direction.
  • TransformingVisioning: reconsider.
  • TransformingOperating: accepted change.
  • OperatingTransforming: improvement.
  • GoverningVisioning: priorities.
  • GoverningTransforming: change authority.
  • GoverningOperating: policy.
  • OperatingGoverning: findings.
Version 1.0 · September 2026 · © 2005–2026 Adrian Sutherland. The arrows show selected exchanges and feedback. Work can repeat within any area or reopen a wider decision. Governing applies to direction, change and operation; the areas can overlap. Retain accepted decisions between cycles.

About this edition

Refreshed for the September 2026 website update. This edition develops the earlier Architecture Portal and ASAF material; the fictional worked example was added in 2026.

Scope, limitations and next checks

Status and accountability

Read this page with its boundaries visible

Status

In development

Last reviewed

Intended users

  • Architects comparing and adapting their existing approach

Non-goals

  • Prescribing a mandatory method or claiming measured benefits

Limitations

  • Guidance illustrated by a fictional example; proposed designs and checks have not been implemented or run.

Next evidence sought

  • Review the guidance and try its records with a practising architect.