It explains how protection needs are addressed across components and their relationships, and how those choices support stakeholder objectives under stated assumptions about threats, risk, technology, operations, and the system lifecycle.
Architecture makes consequential decisions and constraints visible before and during implementation. Different views may describe identity, data, networks, applications, platforms, operations, physical dependencies, or suppliers while remaining traceable to shared requirements.
Key points
Context definitionDefine mission and business objectives, assets, stakeholders, risk tolerance, legal or contractual constraints, threat assumptions, dependencies, and required security properties.
Protection structureEstablish trust boundaries, privilege models, data and control flows, isolation, resilience, monitoring, administration paths, and how controls work together across layers.
TraceabilityConnect requirements to architectural decisions and implemented controls; record assumptions and trade-offs, review changes, and validate the realized system against intended outcomes.
Important limitationAn architecture diagram, reference framework, or control catalog does not prove that the deployed system follows the architecture or resists real threats. Implementation, configuration, operation, and verification determine actual assurance.