Secure Engineering and Supply Chain Operating Model
archimatev1/01 Views
/02 About
Third-party vetting, source integrity, risk-controlled software engineering, testing and monitored production deployment.
Purpose: Third-party vetting, source integrity, risk-controlled software engineering, testing and monitored production deployment. Model family: organization-neutral capability, process, security operations, logical service or system-interaction architecture. Functional groups and cross-domain traces are semantic relationships, not a pixel-level reproduction of any source image. Adaptation: map each service boundary to an owner and deployment, assign protected resources, classify information exchanges, define permit/deny/error behavior, test continuous policy enforcement, and retain decision evidence. Implementing product choices are intentionally out of scope. Origin: independently rebuilt from user-provided historical conceptual security diagrams. Agency, document-control and vendor identifiers are not carried into the model.
Published by Lattix · 20 elements · 20 relationships · validated on publish
/03 Contents
- Role
- Supply chain risk owner
- Process
- Evaluate external suppliers, Prepare development workforce
- Data Store
- Approved dependency and supplier register, Source integrity attestations, Delivery and security evidence
- Application
- Managed source repository, Approved production workload
- Application Component
- Change and code review, Component and dependency scanning, Reproducible isolated build, Artifact signing and provenance, Release admission gate, Production security telemetry, Vulnerability response, Controlled remediation rollout
- Activity
- Build application changes, Execute security and quality tests, Apply secure engineering rules, Promote verified release candidate