Security Architecture
Design and implement comprehensive security architectures that protect systems, data, and users through layered defense strategies, zero trust principles, and risk-based security controls.
Purpose
Security architecture provides the strategic foundation for building resilient, compliant, and trustworthy systems. This skill guides the design of defense-in-depth layers, zero trust implementations, threat modeling methodologies, and mapping to control frameworks (NIST CSF, CIS Controls, ISO 27001).
Unlike tactical security skills (configuring firewalls, implementing authentication, scanning vulnerabilities), security architecture focuses on strategic planning, comprehensive defense strategies, and governance frameworks.
When to Use This Skill
Use security architecture when:
- Designing security for greenfield systems (new applications, cloud migrations)
- Conducting security audits or risk assessments of existing systems
- Implementing zero trust architecture across enterprise environments
- Establishing security governance programs and compliance frameworks
- Threat modeling applications, APIs, or microservices architectures
- Selecting and mapping security controls to regulatory requirements (SOC 2, HIPAA, PCI DSS)
- Designing cloud security architectures (AWS, GCP, Azure multi-account strategies)
- Addressing supply chain security (SLSA framework, SBOM implementation)
Core Security Architecture Principles
1. Defense in Depth
Implement multiple independent layers of security controls so that if one layer fails, others continue to protect critical assets.
9 Defense Layers (2025 Model):
- Physical Security: Data center access, environmental controls, hardware security modules (HSMs)
- Network Perimeter: Next-gen firewalls (NGFW), DDoS protection, web application firewalls (WAF)
- Network Segmentation: VLANs, VPCs, security groups, micro-segmentation
- Endpoint Protection: EDR, antivirus, device encryption, patch management
- Application Layer: Secure coding, WAF, API security, SAST/DAST scanning
- Data Layer: Encryption (at-rest, in-transit, in-use), DLP, backup/recovery
- Identity & Access Management: MFA, SSO, RBAC/ABAC, privileged access management (PAM)
- Behavioral Analytics: UEBA, ML-based anomaly detection, threat intelligence
- Security Operations: SIEM, SOAR, incident response, continuous monitoring
Key Principle: Each layer provides independent protection. Failure of one layer does not compromise the entire system.
For detailed layer-by-layer implementation patterns, see references/defense-in-depth.md.
2. Zero Trust Architecture
Implement "never trust, always verify" principles where every access request is authenticated, authorized, and continuously validated.
Core Zero Trust Principles:
- Continuous Verification: Authenticate and authorize every access request (no implicit trust)
- Least Privilege Access: Grant minimal permissions required, use just-in-time (JIT) access
- Assume Breach: Design systems expecting compromise, limit blast radius
- Explicit Verification: Verify user identity (MFA), device health, application integrity, context (location, time, behavior)
- Micro-Segmentation: Divide networks into small isolated zones, control east-west traffic
Zero Trust Architecture Components:
- Policy Engine: Centralized authorization decision point (allow/deny)
- Identity Provider (IdP): User/machine identity verification (Azure AD, Okta)
- Device Posture Service: Device health checks (MDM, EDR integration)
- Context/Risk Engine: Behavioral analytics, location, time, threat intelligence
- Policy Enforcement Points: Gateways enforcing decisions (ZTNA, API gateways)
For zero trust implementation roadmap and reference architecture, see references/zero-trust-architecture.md.
3. Threat Modeling
Systematically identify, prioritize, and mitigate security threats through structured methodologies.
Primary Methodologies:
| Methodology |
Purpose |
Complexity |
Best For |
| STRIDE |
Threat identification |
Low |
Development teams, quick threat analysis |
| PASTA |
Risk-centric analysis |
High |
Enterprise risk management |
| DREAD |
Risk scoring |
Low |
Prioritizing existing threats |
| Attack Trees |
Visual threat analysis |
Medium |
Security architecture reviews |
STRIDE Threat Categories:
- Spoofing: Attacker impersonates another user/system (Mitigation: MFA, certificate validation)
- Tampering: Unauthorized data modification (Mitigation: Encryption, digital signatures)
- Repudiation: User denies action without proof (Mitigation: Audit logs, non-repudiation)
- Information Disclosure: Confidential data exposure (Mitigation: Encryption, access controls, DLP)
- Denial of Service: System unavailability (Mitigation: Rate limiting, DDoS protection, redundancy)
- Elevation of Privilege: Gaining higher privileges (Mitigation: Least privilege, input validation, patching)
STRIDE Application Process:
- Model the system using data flow diagrams (DFDs)
- Identify threats by applying STRIDE to each component/data flow
- Document threats with STRIDE categories
- Prioritize threats using DREAD scoring or business impact
- Design mitigation controls
For detailed threat modeling methodologies, PASTA process, DREAD scoring, and attack trees, see references/threat-modeling.md. For threat modeling examples, see examples/threat-models/.
Security Control Frameworks
Map security controls to industry frameworks to ensure comprehensive coverage and compliance.
NIST Cybersecurity Framework (CSF) 2.0
6 Core Functions:
- GOVERN (GV): Risk management strategy, policies, supply chain risk management
- IDENTIFY (ID): Asset inventory, risk assessment, continuous improvement
- PROTECT (PR): Access control, data security, platform security, infrastructure resilience
- DETECT (DE): Continuous monitoring, anomaly detection, security event analysis
- RESPOND (RS): Incident management, analysis, communication, mitigation
- RECOVER (RC): Recovery planning, execution, post-incident improvement
Usage: Map security controls to NIST CSF categories to ensure coverage of all security functions. Provides risk-based, flexible framework for security programs.
For detailed NIST CSF category mapping and subcategories, see references/nist-csf-mapping.md.
CIS Critical Security Controls v8
18 Controls organized in 3 Implementation Groups:
- IG1 (Basic): 56 safeguards for small organizations (asset inventory, access control, logging, backups)
- IG2 (Intermediate): +74 safeguards for mid-sized organizations with IT security staff
- IG3 (Advanced): +23 safeguards for large enterprises with dedicated security teams
Top Priority Controls (IG1):
- Inventory and Control of Enterprise Assets
- Inventory and Control of Software Assets
- Data Protection
- Secure Configuration of Enterprise Assets
- Account Management
- Access Control Management
- Continuous Vulnerability Management
- Audit Log Management
Usage: CIS Controls provide prescriptive, measurable security baseline. Start with IG1, progress to IG2/IG3 as security maturity increases.
For detailed CIS Controls implementation guidance, see references/cis-controls.md.
OWASP Top 10 Risk Mitigation
Map OWASP Top 10 application security risks to architectural controls:
| OWASP Risk |
Primary Control |
Framework Mapping |
| Injection |
Parameterized queries, input validation |
NIST PR.DS, CIS 16 |
| Broken Authentication |
MFA, secure session management |
NIST PR.AC, CIS 5, 6 |
| Sensitive Data Exposure |
Encryption, key management |
NIST PR.DS, CIS 3 |
| XXE |
Disable external entities, use JSON |
NIST PR.DS, CIS 16 |
| Broken Access Control |
Authorization checks, RBAC |
NIST PR.AC, CIS 6 |
| Security Misconfiguration |
Hardening, minimal configs |
NIST PR.IP, CIS 4 |
| XSS |
Output encoding, CSP |
NIST PR.DS, CIS 16 |
| Insecure Deserialization |
Validate objects, safe formats |
NIST PR.DS, CIS 16 |
| Known Vulnerabilities |
Patch management, SBOM |
NIST ID.RA, CIS 7 |
| Logging & Monitoring |
SIEM, centralized logging |
NIST DE.CM, CIS 8 |
For detailed OWASP Top 10 mitigation strategies and code examples, see references/owasp-top10-mitigation.md.
Architecture Selection Decision Framework
Select appropriate security architecture approach based on system characteristics:
Greenfield (New System):
- Implement Zero Trust from Day 1
- Identity-first architecture (MFA, SSO, RBAC/ABAC)
- Micro-segmentation by default
- Assume breach mentality (limit blast radius)
- Continuous verification and monitoring
Brownfield (Existing System):
- Hybrid: Maintain Defense in Depth + Zero Trust overlay
- Keep existing perimeter controls (firewalls, VPN)
- Layer Zero Trust controls progressively
- Segment critical assets first (data, admin access)
- Modernize identity and access management
Compliance-Driven:
- Map to control frameworks based on requirements:
- General Security: NIST CSF for risk-based approach
- Baseline Hardening: CIS Controls for prescriptive guidance
- Comprehensive ISMS: ISO 27001 for certification
- Industry-Specific: PCI DSS (payments), HIPAA Security Rule (healthcare), FedRAMP (government)
Cloud-Native:
- Use cloud provider reference architectures:
- AWS: Well-Architected Framework (Security Pillar)
- GCP: Security Best Practices, Security Command Center
- Azure: Security Benchmark, Defender for Cloud
- Implement cloud-native security services (CSPM, CWPP)
Hybrid/Multi-Cloud:
- Cloud Security Posture Management (CSPM) for unified policy enforcement
- Cross-cloud visibility and monitoring
- Cloud-agnostic IAM (Okta, Azure AD)
For detailed architecture selection decision trees, see references/defense-in-depth.md and references/zero-trust-architecture.md.
Supply Chain Security
Protect software supply chain from tampering, backdoors, and compromised dependencies.
SLSA Framework
Supply-chain Levels for Software Artifacts (4 levels):
- SLSA Level 1 - Provenance: Build process generates provenance metadata (not tamper-proof)
- SLSA Level 2 - Hosted Build: Build on trusted platform (GitHub Actions, Cloud Build)
- SLSA Level 3 - Hardened Build: Build platform prevents tampering, audit logs
- SLSA Level 4 - Hermetic, Reproducible: Fully hermetic builds, reproducible, two-party review
Implementation: Start with Level 1 provenance generation, progress to Level 2 (GitHub Actions), then Level 3 (hardened CI/CD with audit logs).
SBOM (Software Bill of Materials)
Generate and maintain inventory of software components and dependencies.
SBOM Standards:
- CycloneDX: OWASP standard (JSON/XML format)
- SPDX: Linux Foundation standard
- SWID: ISO/IEC 19770-2 standard
SBOM Use Cases:
- Vulnerability Management: Quickly identify affected components during CVE disclosures
- License Compliance: Track open-source licenses for legal compliance
- Supply Chain Risk: Visibility into third-party code and dependencies
- Incident Response: Rapid assessment of Log4Shell-type incidents
Dependency Management Best Practices:
- Generate SBOM automatically in CI/CD pipeline
- Continuous scanning with tools (Dependabot, Snyk, Trivy, Grype)
- Automated security patch updates
- License compliance tracking and approval workflows
- Pin dependency versions using lock files
- Minimize dependencies to reduce attack surface
For SLSA implementation guide, SBOM generation examples, and dependency scanning automation, see references/supply-chain-security.md.
Cloud Security Architecture Patterns
AWS Security Architecture
Well-Architected Framework - Security Pillar Principles:
- Strong identity foundation: Centralize IAM, least privilege, IAM Identity Center (SSO)
- Enable traceability: CloudTrail, GuardDuty, Security Hub for comprehensive logging
- Apply security at all layers: Defense in depth across VPC, instances, applications, data
- Automate security best practices: Infrastructure as Code (Terraform, CloudFormation)
- Protect data in transit and at rest: TLS 1.3, AWS KMS, encryption everywhere
Key AWS Security Services:
- IAM: AWS IAM, IAM Identity Center (SSO), Cognito (customer identity)
- Detection: GuardDuty (threat detection), Security Hub (centralized findings), Detective (investigation)
- Network: AWS WAF, Shield (DDoS), Network Firewall
- Data: KMS (key management), Secrets Manager, Macie (data classification)
- Compute: Systems Manager (patch management), Inspector (vulnerability scanning)
Multi-Account Strategy: Use AWS Organizations with Security OU (Security Account, Logging Account, Audit Account) and Workload OUs (Production, Non-Production). Apply Service Control Policies (SCPs) for guardrails.
For AWS reference architectures and multi-account security setup, see references/aws-security-architecture.md and examples/architectures/aws-multi-account-security.md.
GCP Security Architecture
Key GCP Security Services:
- IAM: Cloud IAM, Identity Platform (customer identity), Cloud Identity (workforce)
- Detection: Security Command Center (unified dashboard), Chronicle (SIEM), Event Threat Detection
- Network: Cloud Armor (DDoS/WAF), VPC Service Controls (data exfiltration prevention), Cloud Firewall
- Data: Cloud KMS, Secret Manager, Cloud DLP (data loss prevention)
- Compute: Binary Authorization (image signing), Confidential Computing (encryption in use)
Organization Hierarchy: Structure with Organization → Folders (Production, Non-Production, Security) → Projects. Apply IAM policies at folder level for inheritance.
For GCP security architecture patterns and organization setup, see references/gcp-security-architecture.md and examples/architectures/gcp-security-hierarchy.md.
Azure Security Architecture
Key Azure Security Services:
- IAM: Azure AD (Entra ID), Privileged Identity Management (JIT access), Conditional Access
- Detection: Microsoft Defender for Cloud (CSPM/CWPP), Sentinel (SIEM/SOAR), Azure Monitor
- Network: Azure Firewall, Front Door + WAF, DDoS Protection
- Data: Key Vault (secrets, keys, certificates), Information Protection (DLP), Storage encryption
- Compute: Just-in-Time VM Access, Azure Policy (compliance enforcement)
Hub-Spoke Landing Zone: Implement hub VNet (shared services: firewall, VPN, Azure Bastion) with spoke VNets (workloads). Use Management Groups for policy hierarchy.
For Azure security architecture and hub-spoke design, see references/azure-security-architecture.md and examples/architectures/azure-landing-zone.md.
Identity & Access Management Patterns
Authentication Controls
Multi-Factor Authentication (MFA):
- Types: TOTP (time-based one-time passwords), push notifications, biometrics, hardware tokens (YubiKey, FIDO2)
- Enforcement: Require MFA for all users (workforce and customers), especially privileged accounts
- Passwordless: Transition to WebAuthn, FIDO2, passkeys to eliminate password-based attacks
Single Sign-On (SSO):
- Protocols: SAML 2.0, OAuth 2.0, OpenID Connect (OIDC)
- Benefits: Centralized authentication, reduced password fatigue, improved security posture
- Implementation: Azure AD, Okta, Auth0, Ping Identity
Authorization Controls
Role-Based Access Control (RBAC):
- Users assigned to roles, roles have permissions
- Coarse-grained, simple to implement
- Best for: Organizations with stable role structures
Attribute-Based Access Control (ABAC):
- Fine-grained access based on attributes (user department, resource classification, time, location)
- More flexible than RBAC
- Best for: Complex, dynamic access requirements
Policy-Based Access Control (PBAC):
- Centralized policy engines (Open Policy Agent - OPA, AWS Cedar)
- Policies defined declaratively and versioned
- Best for: Microservices, API gateways, cloud-native architectures
Privileged Access Management (PAM)
Just-in-Time (JIT) Access:
- Temporary elevated privileges for specific tasks
- Time-bound access grants (e.g., 4 hours)
- Reduces standing privileged access
Credential Vaulting:
- Centralized storage of privileged credentials (CyberArk, HashiCorp Vault, Azure Key Vault)
- Automatic password rotation
- Session recording and auditing
For detailed IAM implementation patterns, MFA configuration, and PAM setup, see references/iam-patterns.md.
Security Monitoring & Operations
SIEM (Security Information & Event Management)
Centralize log aggregation, correlation, and alerting for security events.
Leading SIEM Platforms:
- Splunk, Elastic Security, Microsoft Sentinel, Chronicle
SIEM Architecture:
- Log Collection: Ingest logs from all layers (network, endpoints, applications, cloud)
- Normalization: Standardize log formats for correlation
- Correlation: Apply rules to detect patterns (failed logins → brute force attack)
- Alerting: Notify SOC team of high-priority events
- Investigation: Provide search and visualization for incident analysis
SOAR (Security Orchestration, Automation & Response)
Automate incident response workflows to reduce mean time to respond (MTTR).
SOAR Capabilities:
- Playbooks: Automated response workflows (block IP, quarantine endpoint, revoke credentials)
- Orchestration: Integrate with security tools (SIEM, EDR, firewall, IAM)
- Case Management: Track incidents, assign to analysts, document resolution
Leading SOAR Platforms:
- Splunk SOAR, Palo Alto Cortex XSOAR, IBM Resilient
Detection Strategies
UEBA (User & Entity Behavior Analytics):
- Machine learning-based anomaly detection
- Detects: Account compromise, insider threats, data exfiltration
- Baseline normal behavior, alert on deviations
Threat Intelligence:
- Integrate threat feeds (MISP, ThreatConnect, ISACs)
- Enrich alerts with threat context (known malicious IPs, IOCs)
- Proactive threat hunting using TTPs (MITRE ATT&CK framework)
For SIEM architecture, SOAR playbook examples, and detection strategies, see references/security-operations.md.
Quick Reference: Control Framework Mapping
Use this table to map risks to appropriate control frameworks:
| Risk/Requirement |
Framework |
Key Controls |
| General security program |
NIST CSF 2.0 |
All 6 functions (GV, ID, PR, DE, RS, RC) |
| Compliance baseline |
CIS Controls v8 |
IG1: Controls 1-18 (56 safeguards) |
| ISO certification |
ISO 27001/27002 |
114 controls across 14 domains |
| Application security |
OWASP ASVS |
286 security requirements (3 levels) |
| Cloud security (AWS) |
AWS Well-Architected |
Security Pillar: 10 design principles |
| Cloud security (GCP) |
GCP Security Best Practices |
Security Command Center architecture |
| Cloud security (Azure) |
Azure Security Benchmark |
Defender for Cloud controls |
| Supply chain security |
SLSA + SBOM |
Level 2+ SLSA, CycloneDX SBOM |
| Zero trust architecture |
NIST SP 800-207 |
ZTA tenets, deployment models |
| Privacy/GDPR |
NIST Privacy Framework |
Privacy engineering objectives |
Integration with Related Skills
Security architecture provides the strategic foundation for tactical security implementations:
infrastructure-as-code: Implement security architecture as code (secure defaults, hardening)
kubernetes-operations: Apply K8s security architecture (RBAC, Pod Security, Network Policies)
secret-management: Architect secrets management (KMS, Vault, rotation strategies)
building-ci-pipelines: Secure CI/CD architecture (SAST/DAST integration, artifact signing)
configuring-firewalls: Implement network perimeter layer of defense-in-depth
vulnerability-management: Integrate vulnerability scanning into security architecture
auth-security: Implement IAM layer details (MFA, RBAC/ABAC, session management)
siem-logging: Implement security monitoring architecture (SIEM, log aggregation)
compliance-frameworks: Map security architecture to compliance requirements
Common Security Architecture Patterns
Pattern 1: Zero Trust Network Access (ZTNA)
Replace VPN with identity-based access to applications.
Architecture:
- User authenticates to identity provider (Azure AD, Okta)
- Device posture check validates device health
- Policy engine evaluates access request (user, device, context)
- Access granted through secure connector (no network access)
Benefits: Eliminates lateral movement, reduces attack surface, improves user experience
Pattern 2: Defense in Depth for Web Applications
Layer multiple security controls for web application protection.
Layers:
- DDoS Protection (Cloudflare, AWS Shield)
- WAF (application firewall, OWASP Top 10 rules)
- API Gateway (authentication, rate limiting)
- Application Security (SAST/DAST, secure coding)
- Database Security (encryption, least privilege)
- Logging & Monitoring (SIEM, anomaly detection)
Pattern 3: Cloud Security Posture Management (CSPM)
Continuously monitor and enforce security configurations across cloud environments.
Architecture:
- Asset Discovery: Inventory all cloud resources
- Configuration Assessment: Compare against security baselines (CIS Benchmarks)
- Compliance Monitoring: Track regulatory compliance (SOC 2, ISO 27001)
- Remediation: Automated fixes or guided workflows
- Drift Detection: Alert on configuration changes
Leading CSPM Tools: Wiz, Orca Security, Prisma Cloud, Microsoft Defender for Cloud
Resources and References
Defense in Depth:
references/defense-in-depth.md - 9-layer defense model, implementation patterns, failure impact analysis
Zero Trust Architecture:
references/zero-trust-architecture.md - ZTA principles, reference architecture, implementation roadmap
Threat Modeling:
references/threat-modeling.md - STRIDE, PASTA, DREAD, Attack Trees methodologies
examples/threat-models/web-app-stride.md - Web application STRIDE analysis example
examples/threat-models/api-threat-model.md - REST API threat model example
examples/threat-models/microservices-threat-model.md - Microservices threat model example
Control Frameworks:
references/nist-csf-mapping.md - NIST CSF 2.0 functions, categories, subcategories
references/cis-controls.md - CIS Controls v8, implementation groups, safeguards
references/owasp-top10-mitigation.md - OWASP Top 10 risks and mitigation strategies
Supply Chain Security:
references/supply-chain-security.md - SLSA framework, SBOM generation, dependency scanning
Cloud Security:
references/aws-security-architecture.md - AWS Well-Architected Security Pillar, services, patterns
references/gcp-security-architecture.md - GCP Security Best Practices, services, organization design
references/azure-security-architecture.md - Azure Security Benchmark, Defender for Cloud, landing zones
IAM & Operations:
references/iam-patterns.md - Authentication, authorization, MFA, RBAC/ABAC, PAM
references/security-operations.md - SIEM, SOAR, UEBA, threat intelligence, incident response
Architecture Examples:
examples/architectures/aws-multi-account-security.md - AWS Organizations security setup
examples/architectures/gcp-security-hierarchy.md - GCP folder/project security hierarchy
examples/architectures/azure-landing-zone.md - Azure hub-spoke landing zone
examples/architectures/zero-trust-network.md - Zero trust network design
Scripts:
scripts/threat-model-template.py - Generate STRIDE threat model templates
scripts/control-gap-analysis.sh - Compare current controls against frameworks
scripts/sbom-generate.sh - Generate SBOM in CycloneDX format
scripts/security-checklist.sh - Automated security architecture checklist
Summary
Security architecture requires strategic planning across multiple layers, from physical security to security operations. Implement defense-in-depth for comprehensive protection, adopt zero trust principles for modern cloud environments, use threat modeling to identify risks proactively, and map controls to frameworks for compliance and completeness.
Start with risk assessment to understand threats, select appropriate architecture approach (zero trust for greenfield, hybrid for brownfield), implement layered controls, and continuously monitor and improve security posture.
1---2name: architecting-security3description: Design comprehensive security architectures using defense-in-depth, zero trust principles, threat modeling (STRIDE, PASTA), and control frameworks (NIST CSF, CIS Controls, ISO 27001). Use when designing security for new systems, auditing existing architectures, or establishing security governance programs.4---5
6# Security Architecture
7
8Design and implement comprehensive security architectures that protect systems, data, and users through layered defense strategies, zero trust principles, and risk-based security controls.
9
10## Purpose
11
12Security architecture provides the strategic foundation for building resilient, compliant, and trustworthy systems. This skill guides the design of defense-in-depth layers, zero trust implementations, threat modeling methodologies, and mapping to control frameworks (NIST CSF, CIS Controls, ISO 27001).
13
14Unlike tactical security skills (configuring firewalls, implementing authentication, scanning vulnerabilities), security architecture focuses on strategic planning, comprehensive defense strategies, and governance frameworks.
15
16## When to Use This Skill
17
18Use security architecture when:
19
20- Designing security for greenfield systems (new applications, cloud migrations)
21- Conducting security audits or risk assessments of existing systems
22- Implementing zero trust architecture across enterprise environments
23- Establishing security governance programs and compliance frameworks
24- Threat modeling applications, APIs, or microservices architectures
25- Selecting and mapping security controls to regulatory requirements (SOC 2, HIPAA, PCI DSS)
26- Designing cloud security architectures (AWS, GCP, Azure multi-account strategies)
27- Addressing supply chain security (SLSA framework, SBOM implementation)
28
29## Core Security Architecture Principles
30
31### 1. Defense in Depth
32
33Implement multiple independent layers of security controls so that if one layer fails, others continue to protect critical assets.
34
35**9 Defense Layers (2025 Model):**
36
371. **Physical Security:** Data center access, environmental controls, hardware security modules (HSMs)
382. **Network Perimeter:** Next-gen firewalls (NGFW), DDoS protection, web application firewalls (WAF)
393. **Network Segmentation:** VLANs, VPCs, security groups, micro-segmentation
404. **Endpoint Protection:** EDR, antivirus, device encryption, patch management
415. **Application Layer:** Secure coding, WAF, API security, SAST/DAST scanning
426. **Data Layer:** Encryption (at-rest, in-transit, in-use), DLP, backup/recovery
437. **Identity & Access Management:** MFA, SSO, RBAC/ABAC, privileged access management (PAM)
448. **Behavioral Analytics:** UEBA, ML-based anomaly detection, threat intelligence
459. **Security Operations:** SIEM, SOAR, incident response, continuous monitoring
46
47**Key Principle:** Each layer provides independent protection. Failure of one layer does not compromise the entire system.
48
49For detailed layer-by-layer implementation patterns, see `references/defense-in-depth.md`.
50
51### 2. Zero Trust Architecture
52
53Implement "never trust, always verify" principles where every access request is authenticated, authorized, and continuously validated.
54
55**Core Zero Trust Principles:**
56
571. **Continuous Verification:** Authenticate and authorize every access request (no implicit trust)
582. **Least Privilege Access:** Grant minimal permissions required, use just-in-time (JIT) access
593. **Assume Breach:** Design systems expecting compromise, limit blast radius
604. **Explicit Verification:** Verify user identity (MFA), device health, application integrity, context (location, time, behavior)
615. **Micro-Segmentation:** Divide networks into small isolated zones, control east-west traffic
62
63**Zero Trust Architecture Components:**
64
65- **Policy Engine:** Centralized authorization decision point (allow/deny)
66- **Identity Provider (IdP):** User/machine identity verification (Azure AD, Okta)
67- **Device Posture Service:** Device health checks (MDM, EDR integration)
68- **Context/Risk Engine:** Behavioral analytics, location, time, threat intelligence
69- **Policy Enforcement Points:** Gateways enforcing decisions (ZTNA, API gateways)
70
71For zero trust implementation roadmap and reference architecture, see `references/zero-trust-architecture.md`.
72
73### 3. Threat Modeling
74
75Systematically identify, prioritize, and mitigate security threats through structured methodologies.
76
77**Primary Methodologies:**
78
79| Methodology | Purpose | Complexity | Best For |
80|-------------|---------|------------|----------|
81| **STRIDE** | Threat identification | Low | Development teams, quick threat analysis |
82| **PASTA** | Risk-centric analysis | High | Enterprise risk management |
83| **DREAD** | Risk scoring | Low | Prioritizing existing threats |
84| **Attack Trees** | Visual threat analysis | Medium | Security architecture reviews |
85
86**STRIDE Threat Categories:**
87
88- **S**poofing: Attacker impersonates another user/system (Mitigation: MFA, certificate validation)
89- **T**ampering: Unauthorized data modification (Mitigation: Encryption, digital signatures)
90- **R**epudiation: User denies action without proof (Mitigation: Audit logs, non-repudiation)
91- **I**nformation Disclosure: Confidential data exposure (Mitigation: Encryption, access controls, DLP)
92- **D**enial of Service: System unavailability (Mitigation: Rate limiting, DDoS protection, redundancy)
93- **E**levation of Privilege: Gaining higher privileges (Mitigation: Least privilege, input validation, patching)
94
95**STRIDE Application Process:**
96
971. Model the system using data flow diagrams (DFDs)
982. Identify threats by applying STRIDE to each component/data flow
993. Document threats with STRIDE categories
1004. Prioritize threats using DREAD scoring or business impact
1015. Design mitigation controls
102
103For detailed threat modeling methodologies, PASTA process, DREAD scoring, and attack trees, see `references/threat-modeling.md`. For threat modeling examples, see `examples/threat-models/`.
104
105## Security Control Frameworks
106
107Map security controls to industry frameworks to ensure comprehensive coverage and compliance.
108
109### NIST Cybersecurity Framework (CSF) 2.0
110
111**6 Core Functions:**
112
1131. **GOVERN (GV):** Risk management strategy, policies, supply chain risk management
1142. **IDENTIFY (ID):** Asset inventory, risk assessment, continuous improvement
1153. **PROTECT (PR):** Access control, data security, platform security, infrastructure resilience
1164. **DETECT (DE):** Continuous monitoring, anomaly detection, security event analysis
1175. **RESPOND (RS):** Incident management, analysis, communication, mitigation
1186. **RECOVER (RC):** Recovery planning, execution, post-incident improvement
119
120**Usage:** Map security controls to NIST CSF categories to ensure coverage of all security functions. Provides risk-based, flexible framework for security programs.
121
122For detailed NIST CSF category mapping and subcategories, see `references/nist-csf-mapping.md`.
123
124### CIS Critical Security Controls v8
125
126**18 Controls organized in 3 Implementation Groups:**
127
128- **IG1 (Basic):** 56 safeguards for small organizations (asset inventory, access control, logging, backups)
129- **IG2 (Intermediate):** +74 safeguards for mid-sized organizations with IT security staff
130- **IG3 (Advanced):** +23 safeguards for large enterprises with dedicated security teams
131
132**Top Priority Controls (IG1):**
1331. Inventory and Control of Enterprise Assets
1342. Inventory and Control of Software Assets
1353. Data Protection
1364. Secure Configuration of Enterprise Assets
1375. Account Management
1386. Access Control Management
1397. Continuous Vulnerability Management
1408. Audit Log Management
141
142**Usage:** CIS Controls provide prescriptive, measurable security baseline. Start with IG1, progress to IG2/IG3 as security maturity increases.
143
144For detailed CIS Controls implementation guidance, see `references/cis-controls.md`.
145
146### OWASP Top 10 Risk Mitigation
147
148Map OWASP Top 10 application security risks to architectural controls:
149
150| OWASP Risk | Primary Control | Framework Mapping |
151|------------|-----------------|-------------------|
152| **Injection** | Parameterized queries, input validation | NIST PR.DS, CIS 16 |
153| **Broken Authentication** | MFA, secure session management | NIST PR.AC, CIS 5, 6 |
154| **Sensitive Data Exposure** | Encryption, key management | NIST PR.DS, CIS 3 |
155| **XXE** | Disable external entities, use JSON | NIST PR.DS, CIS 16 |
156| **Broken Access Control** | Authorization checks, RBAC | NIST PR.AC, CIS 6 |
157| **Security Misconfiguration** | Hardening, minimal configs | NIST PR.IP, CIS 4 |
158| **XSS** | Output encoding, CSP | NIST PR.DS, CIS 16 |
159| **Insecure Deserialization** | Validate objects, safe formats | NIST PR.DS, CIS 16 |
160| **Known Vulnerabilities** | Patch management, SBOM | NIST ID.RA, CIS 7 |
161| **Logging & Monitoring** | SIEM, centralized logging | NIST DE.CM, CIS 8 |
162
163For detailed OWASP Top 10 mitigation strategies and code examples, see `references/owasp-top10-mitigation.md`.
164
165## Architecture Selection Decision Framework
166
167Select appropriate security architecture approach based on system characteristics:
168
169**Greenfield (New System):**
170- Implement Zero Trust from Day 1
171- Identity-first architecture (MFA, SSO, RBAC/ABAC)
172- Micro-segmentation by default
173- Assume breach mentality (limit blast radius)
174- Continuous verification and monitoring
175
176**Brownfield (Existing System):**
177- Hybrid: Maintain Defense in Depth + Zero Trust overlay
178- Keep existing perimeter controls (firewalls, VPN)
179- Layer Zero Trust controls progressively
180- Segment critical assets first (data, admin access)
181- Modernize identity and access management
182
183**Compliance-Driven:**
184- Map to control frameworks based on requirements:
185 - **General Security:** NIST CSF for risk-based approach
186 - **Baseline Hardening:** CIS Controls for prescriptive guidance
187 - **Comprehensive ISMS:** ISO 27001 for certification
188 - **Industry-Specific:** PCI DSS (payments), HIPAA Security Rule (healthcare), FedRAMP (government)
189
190**Cloud-Native:**
191- Use cloud provider reference architectures:
192 - **AWS:** Well-Architected Framework (Security Pillar)
193 - **GCP:** Security Best Practices, Security Command Center
194 - **Azure:** Security Benchmark, Defender for Cloud
195- Implement cloud-native security services (CSPM, CWPP)
196
197**Hybrid/Multi-Cloud:**
198- Cloud Security Posture Management (CSPM) for unified policy enforcement
199- Cross-cloud visibility and monitoring
200- Cloud-agnostic IAM (Okta, Azure AD)
201
202For detailed architecture selection decision trees, see `references/defense-in-depth.md` and `references/zero-trust-architecture.md`.
203
204## Supply Chain Security
205
206Protect software supply chain from tampering, backdoors, and compromised dependencies.
207
208### SLSA Framework
209
210**Supply-chain Levels for Software Artifacts (4 levels):**
211
2121. **SLSA Level 1 - Provenance:** Build process generates provenance metadata (not tamper-proof)
2132. **SLSA Level 2 - Hosted Build:** Build on trusted platform (GitHub Actions, Cloud Build)
2143. **SLSA Level 3 - Hardened Build:** Build platform prevents tampering, audit logs
2154. **SLSA Level 4 - Hermetic, Reproducible:** Fully hermetic builds, reproducible, two-party review
216
217**Implementation:** Start with Level 1 provenance generation, progress to Level 2 (GitHub Actions), then Level 3 (hardened CI/CD with audit logs).
218
219### SBOM (Software Bill of Materials)
220
221Generate and maintain inventory of software components and dependencies.
222
223**SBOM Standards:**
224- **CycloneDX:** OWASP standard (JSON/XML format)
225- **SPDX:** Linux Foundation standard
226- **SWID:** ISO/IEC 19770-2 standard
227
228**SBOM Use Cases:**
229- Vulnerability Management: Quickly identify affected components during CVE disclosures
230- License Compliance: Track open-source licenses for legal compliance
231- Supply Chain Risk: Visibility into third-party code and dependencies
232- Incident Response: Rapid assessment of Log4Shell-type incidents
233
234**Dependency Management Best Practices:**
2351. Generate SBOM automatically in CI/CD pipeline
2362. Continuous scanning with tools (Dependabot, Snyk, Trivy, Grype)
2373. Automated security patch updates
2384. License compliance tracking and approval workflows
2395. Pin dependency versions using lock files
2406. Minimize dependencies to reduce attack surface
241
242For SLSA implementation guide, SBOM generation examples, and dependency scanning automation, see `references/supply-chain-security.md`.
243
244## Cloud Security Architecture Patterns
245
246### AWS Security Architecture
247
248**Well-Architected Framework - Security Pillar Principles:**
249
2501. **Strong identity foundation:** Centralize IAM, least privilege, IAM Identity Center (SSO)
2512. **Enable traceability:** CloudTrail, GuardDuty, Security Hub for comprehensive logging
2523. **Apply security at all layers:** Defense in depth across VPC, instances, applications, data
2534. **Automate security best practices:** Infrastructure as Code (Terraform, CloudFormation)
2545. **Protect data in transit and at rest:** TLS 1.3, AWS KMS, encryption everywhere
255
256**Key AWS Security Services:**
257
258- **IAM:** AWS IAM, IAM Identity Center (SSO), Cognito (customer identity)
259- **Detection:** GuardDuty (threat detection), Security Hub (centralized findings), Detective (investigation)
260- **Network:** AWS WAF, Shield (DDoS), Network Firewall
261- **Data:** KMS (key management), Secrets Manager, Macie (data classification)
262- **Compute:** Systems Manager (patch management), Inspector (vulnerability scanning)
263
264**Multi-Account Strategy:** Use AWS Organizations with Security OU (Security Account, Logging Account, Audit Account) and Workload OUs (Production, Non-Production). Apply Service Control Policies (SCPs) for guardrails.
265
266For AWS reference architectures and multi-account security setup, see `references/aws-security-architecture.md` and `examples/architectures/aws-multi-account-security.md`.
267
268### GCP Security Architecture
269
270**Key GCP Security Services:**
271
272- **IAM:** Cloud IAM, Identity Platform (customer identity), Cloud Identity (workforce)
273- **Detection:** Security Command Center (unified dashboard), Chronicle (SIEM), Event Threat Detection
274- **Network:** Cloud Armor (DDoS/WAF), VPC Service Controls (data exfiltration prevention), Cloud Firewall
275- **Data:** Cloud KMS, Secret Manager, Cloud DLP (data loss prevention)
276- **Compute:** Binary Authorization (image signing), Confidential Computing (encryption in use)
277
278**Organization Hierarchy:** Structure with Organization → Folders (Production, Non-Production, Security) → Projects. Apply IAM policies at folder level for inheritance.
279
280For GCP security architecture patterns and organization setup, see `references/gcp-security-architecture.md` and `examples/architectures/gcp-security-hierarchy.md`.
281
282### Azure Security Architecture
283
284**Key Azure Security Services:**
285
286- **IAM:** Azure AD (Entra ID), Privileged Identity Management (JIT access), Conditional Access
287- **Detection:** Microsoft Defender for Cloud (CSPM/CWPP), Sentinel (SIEM/SOAR), Azure Monitor
288- **Network:** Azure Firewall, Front Door + WAF, DDoS Protection
289- **Data:** Key Vault (secrets, keys, certificates), Information Protection (DLP), Storage encryption
290- **Compute:** Just-in-Time VM Access, Azure Policy (compliance enforcement)
291
292**Hub-Spoke Landing Zone:** Implement hub VNet (shared services: firewall, VPN, Azure Bastion) with spoke VNets (workloads). Use Management Groups for policy hierarchy.
293
294For Azure security architecture and hub-spoke design, see `references/azure-security-architecture.md` and `examples/architectures/azure-landing-zone.md`.
295
296## Identity & Access Management Patterns
297
298### Authentication Controls
299
300**Multi-Factor Authentication (MFA):**
301- **Types:** TOTP (time-based one-time passwords), push notifications, biometrics, hardware tokens (YubiKey, FIDO2)
302- **Enforcement:** Require MFA for all users (workforce and customers), especially privileged accounts
303- **Passwordless:** Transition to WebAuthn, FIDO2, passkeys to eliminate password-based attacks
304
305**Single Sign-On (SSO):**
306- **Protocols:** SAML 2.0, OAuth 2.0, OpenID Connect (OIDC)
307- **Benefits:** Centralized authentication, reduced password fatigue, improved security posture
308- **Implementation:** Azure AD, Okta, Auth0, Ping Identity
309
310### Authorization Controls
311
312**Role-Based Access Control (RBAC):**
313- Users assigned to roles, roles have permissions
314- Coarse-grained, simple to implement
315- Best for: Organizations with stable role structures
316
317**Attribute-Based Access Control (ABAC):**
318- Fine-grained access based on attributes (user department, resource classification, time, location)
319- More flexible than RBAC
320- Best for: Complex, dynamic access requirements
321
322**Policy-Based Access Control (PBAC):**
323- Centralized policy engines (Open Policy Agent - OPA, AWS Cedar)
324- Policies defined declaratively and versioned
325- Best for: Microservices, API gateways, cloud-native architectures
326
327### Privileged Access Management (PAM)
328
329**Just-in-Time (JIT) Access:**
330- Temporary elevated privileges for specific tasks
331- Time-bound access grants (e.g., 4 hours)
332- Reduces standing privileged access
333
334**Credential Vaulting:**
335- Centralized storage of privileged credentials (CyberArk, HashiCorp Vault, Azure Key Vault)
336- Automatic password rotation
337- Session recording and auditing
338
339For detailed IAM implementation patterns, MFA configuration, and PAM setup, see `references/iam-patterns.md`.
340
341## Security Monitoring & Operations
342
343### SIEM (Security Information & Event Management)
344
345Centralize log aggregation, correlation, and alerting for security events.
346
347**Leading SIEM Platforms:**
348- Splunk, Elastic Security, Microsoft Sentinel, Chronicle
349
350**SIEM Architecture:**
3511. **Log Collection:** Ingest logs from all layers (network, endpoints, applications, cloud)
3522. **Normalization:** Standardize log formats for correlation
3533. **Correlation:** Apply rules to detect patterns (failed logins → brute force attack)
3544. **Alerting:** Notify SOC team of high-priority events
3555. **Investigation:** Provide search and visualization for incident analysis
356
357### SOAR (Security Orchestration, Automation & Response)
358
359Automate incident response workflows to reduce mean time to respond (MTTR).
360
361**SOAR Capabilities:**
362- **Playbooks:** Automated response workflows (block IP, quarantine endpoint, revoke credentials)
363- **Orchestration:** Integrate with security tools (SIEM, EDR, firewall, IAM)
364- **Case Management:** Track incidents, assign to analysts, document resolution
365
366**Leading SOAR Platforms:**
367- Splunk SOAR, Palo Alto Cortex XSOAR, IBM Resilient
368
369### Detection Strategies
370
371**UEBA (User & Entity Behavior Analytics):**
372- Machine learning-based anomaly detection
373- Detects: Account compromise, insider threats, data exfiltration
374- Baseline normal behavior, alert on deviations
375
376**Threat Intelligence:**
377- Integrate threat feeds (MISP, ThreatConnect, ISACs)
378- Enrich alerts with threat context (known malicious IPs, IOCs)
379- Proactive threat hunting using TTPs (MITRE ATT&CK framework)
380
381For SIEM architecture, SOAR playbook examples, and detection strategies, see `references/security-operations.md`.
382
383## Quick Reference: Control Framework Mapping
384
385Use this table to map risks to appropriate control frameworks:
386
387| Risk/Requirement | Framework | Key Controls |
388|------------------|-----------|--------------|
389| General security program | NIST CSF 2.0 | All 6 functions (GV, ID, PR, DE, RS, RC) |
390| Compliance baseline | CIS Controls v8 | IG1: Controls 1-18 (56 safeguards) |
391| ISO certification | ISO 27001/27002 | 114 controls across 14 domains |
392| Application security | OWASP ASVS | 286 security requirements (3 levels) |
393| Cloud security (AWS) | AWS Well-Architected | Security Pillar: 10 design principles |
394| Cloud security (GCP) | GCP Security Best Practices | Security Command Center architecture |
395| Cloud security (Azure) | Azure Security Benchmark | Defender for Cloud controls |
396| Supply chain security | SLSA + SBOM | Level 2+ SLSA, CycloneDX SBOM |
397| Zero trust architecture | NIST SP 800-207 | ZTA tenets, deployment models |
398| Privacy/GDPR | NIST Privacy Framework | Privacy engineering objectives |
399
400## Integration with Related Skills
401
402Security architecture provides the strategic foundation for tactical security implementations:
403
404- **`infrastructure-as-code`:** Implement security architecture as code (secure defaults, hardening)
405- **`kubernetes-operations`:** Apply K8s security architecture (RBAC, Pod Security, Network Policies)
406- **`secret-management`:** Architect secrets management (KMS, Vault, rotation strategies)
407- **`building-ci-pipelines`:** Secure CI/CD architecture (SAST/DAST integration, artifact signing)
408- **`configuring-firewalls`:** Implement network perimeter layer of defense-in-depth
409- **`vulnerability-management`:** Integrate vulnerability scanning into security architecture
410- **`auth-security`:** Implement IAM layer details (MFA, RBAC/ABAC, session management)
411- **`siem-logging`:** Implement security monitoring architecture (SIEM, log aggregation)
412- **`compliance-frameworks`:** Map security architecture to compliance requirements
413
414## Common Security Architecture Patterns
415
416### Pattern 1: Zero Trust Network Access (ZTNA)
417
418Replace VPN with identity-based access to applications.
419
420**Architecture:**
4211. User authenticates to identity provider (Azure AD, Okta)
4222. Device posture check validates device health
4233. Policy engine evaluates access request (user, device, context)
4244. Access granted through secure connector (no network access)
425
426**Benefits:** Eliminates lateral movement, reduces attack surface, improves user experience
427
428### Pattern 2: Defense in Depth for Web Applications
429
430Layer multiple security controls for web application protection.
431
432**Layers:**
4331. DDoS Protection (Cloudflare, AWS Shield)
4342. WAF (application firewall, OWASP Top 10 rules)
4353. API Gateway (authentication, rate limiting)
4364. Application Security (SAST/DAST, secure coding)
4375. Database Security (encryption, least privilege)
4386. Logging & Monitoring (SIEM, anomaly detection)
439
440### Pattern 3: Cloud Security Posture Management (CSPM)
441
442Continuously monitor and enforce security configurations across cloud environments.
443
444**Architecture:**
4451. Asset Discovery: Inventory all cloud resources
4462. Configuration Assessment: Compare against security baselines (CIS Benchmarks)
4473. Compliance Monitoring: Track regulatory compliance (SOC 2, ISO 27001)
4484. Remediation: Automated fixes or guided workflows
4495. Drift Detection: Alert on configuration changes
450
451**Leading CSPM Tools:** Wiz, Orca Security, Prisma Cloud, Microsoft Defender for Cloud
452
453## Resources and References
454
455**Defense in Depth:**
456- `references/defense-in-depth.md` - 9-layer defense model, implementation patterns, failure impact analysis
457
458**Zero Trust Architecture:**
459- `references/zero-trust-architecture.md` - ZTA principles, reference architecture, implementation roadmap
460
461**Threat Modeling:**
462- `references/threat-modeling.md` - STRIDE, PASTA, DREAD, Attack Trees methodologies
463- `examples/threat-models/web-app-stride.md` - Web application STRIDE analysis example
464- `examples/threat-models/api-threat-model.md` - REST API threat model example
465- `examples/threat-models/microservices-threat-model.md` - Microservices threat model example
466
467**Control Frameworks:**
468- `references/nist-csf-mapping.md` - NIST CSF 2.0 functions, categories, subcategories
469- `references/cis-controls.md` - CIS Controls v8, implementation groups, safeguards
470- `references/owasp-top10-mitigation.md` - OWASP Top 10 risks and mitigation strategies
471
472**Supply Chain Security:**
473- `references/supply-chain-security.md` - SLSA framework, SBOM generation, dependency scanning
474
475**Cloud Security:**
476- `references/aws-security-architecture.md` - AWS Well-Architected Security Pillar, services, patterns
477- `references/gcp-security-architecture.md` - GCP Security Best Practices, services, organization design
478- `references/azure-security-architecture.md` - Azure Security Benchmark, Defender for Cloud, landing zones
479
480**IAM & Operations:**
481- `references/iam-patterns.md` - Authentication, authorization, MFA, RBAC/ABAC, PAM
482- `references/security-operations.md` - SIEM, SOAR, UEBA, threat intelligence, incident response
483
484**Architecture Examples:**
485- `examples/architectures/aws-multi-account-security.md` - AWS Organizations security setup
486- `examples/architectures/gcp-security-hierarchy.md` - GCP folder/project security hierarchy
487- `examples/architectures/azure-landing-zone.md` - Azure hub-spoke landing zone
488- `examples/architectures/zero-trust-network.md` - Zero trust network design
489
490**Scripts:**
491- `scripts/threat-model-template.py` - Generate STRIDE threat model templates
492- `scripts/control-gap-analysis.sh` - Compare current controls against frameworks
493- `scripts/sbom-generate.sh` - Generate SBOM in CycloneDX format
494- `scripts/security-checklist.sh` - Automated security architecture checklist
495
496## Summary
497
498Security architecture requires strategic planning across multiple layers, from physical security to security operations. Implement defense-in-depth for comprehensive protection, adopt zero trust principles for modern cloud environments, use threat modeling to identify risks proactively, and map controls to frameworks for compliance and completeness.
499
500Start with risk assessment to understand threats, select appropriate architecture approach (zero trust for greenfield, hybrid for brownfield), implement layered controls, and continuously monitor and improve security posture.