Data-Centric Security — enterprise reference architecture
securityv1/01 Views
/02 About
Enterprise-wide protection of information across discovery, classification, contextual policy, use, sharing, cryptography, revocation and assurance.
Purpose: Enterprise-wide protection of information across discovery, classification, contextual policy, use, sharing, cryptography, revocation and assurance. Architecture scope: independently reconstructed reference responsibilities, operational flows, policy decisions, assurance concerns, exception pathways and security boundaries. Grouped viewpoints describe coherent service or activity sequences. Focused trace views expose inter-domain obligations and information exchanges. Adoption: refine control and data-flow semantics to the enterprise ecosystem; map resource owners, role and workload identities, interfaces, failure policies, information classification, privacy obligations, deployment options and operational evidence. Reference elements alone do not establish an authorization, compliance result, formal proof, cryptographic assurance, or production readiness. Public conceptual basis: https://csrc.nist.gov/pubs/sp/800/162/upd2/final. This is an original Arq vendor-neutral interpretation, not an official implementation diagram or an endorsed/certified solution.
Published by Lattix · 24 elements · 27 relationships · validated on publish
/03 Contents
- Role
- Information owner, Policy authority
- Process
- Discover information assets, Classify and label data
- Data Domain
- Governed information
- Policy
- Data usage and retention policy
- Application Component
- Policy decision service, Policy enforcement point, Protected data access gateway, Resource authorization guard, Authorized transformation service, Cryptographic key authority, Encryption service, Protected write service, Controlled information exchange, Recipient entitlement check, Revocation distributor
- Data Store
- Protected records, Encrypted data objects, Decision and revocation evidence
- Activity
- Ingest or create information, Apply handling labels, Retain and review data, Authorize secure disposal