Define the security architecture
Security architecture translates business objectives, security requirements, risk decisions, and operational constraints into an organized set of trust boundaries, components, interfaces, control responsibilities, and design rules.
Example: Establish system scope and context, identify assets, actors, data flows, and trust relationships, allocate control responsibilities, and document assumptions and residual risk.
Counterexample: Treat a product list or network diagram alone as a security architecture, which overstates what one safeguard can establish. | Assign all duties for security architecture to one component without checking gaps, duplication, or concentration risk, leaving control ownership unclear, while system-wide failure behavior remains unresolved. | Write implementation tasks for security architecture before agreeing on system context and trust boundaries, deferring architectural judgment.
Limitations: Do not treat a product list or network diagram alone as a security architecture.