Data-Centric Security — enterprise reference architecture

securityv1

/01 Views

Discovery and classificationsecurity
Governance and policysecurity
Resource accesssecurity
Cryptographic protectionsecurity
Cross-boundary sharing and revocationsecurity
Information lifecyclesecurity
Data usage and retention policy → Protected data access gatewaysecurity
Data usage and retention policy → Recipient entitlement checksecurity
Policy decision service → Resource authorization guardsecurity
Policy decision service → Revocation distributorsecurity
Policy enforcement point → Protected data access gatewaysecurity
Controlled information exchange → Protected recordssecurity
Classify and label data → Apply handling labelssecurity
Resource authorization guard → Encryption servicesecurity
Information owner → Data usage and retention policysecurity

/02 About

Enterprise-wide protection of information across discovery, classification, contextual policy, use, sharing, cryptography, revocation and assurance.

Purpose: Enterprise-wide protection of information across discovery, classification, contextual policy, use, sharing, cryptography, revocation and assurance. Architecture scope: independently reconstructed reference responsibilities, operational flows, policy decisions, assurance concerns, exception pathways and security boundaries. Grouped viewpoints describe coherent service or activity sequences. Focused trace views expose inter-domain obligations and information exchanges. Adoption: refine control and data-flow semantics to the enterprise ecosystem; map resource owners, role and workload identities, interfaces, failure policies, information classification, privacy obligations, deployment options and operational evidence. Reference elements alone do not establish an authorization, compliance result, formal proof, cryptographic assurance, or production readiness. Public conceptual basis: https://csrc.nist.gov/pubs/sp/800/162/upd2/final. This is an original Arq vendor-neutral interpretation, not an official implementation diagram or an endorsed/certified solution.

Published by Lattix · 24 elements · 27 relationships · validated on publish

/03 Contents

Role
Information owner, Policy authority
Process
Discover information assets, Classify and label data
Data Domain
Governed information
Policy
Data usage and retention policy
Application Component
Policy decision service, Policy enforcement point, Protected data access gateway, Resource authorization guard, Authorized transformation service, Cryptographic key authority, Encryption service, Protected write service, Controlled information exchange, Recipient entitlement check, Revocation distributor
Data Store
Protected records, Encrypted data objects, Decision and revocation evidence
Activity
Ingest or create information, Apply handling labels, Retain and review data, Authorize secure disposal
Data-Centric Security — enterprise reference architecture · Architecture hub · Arq