Purpose
Architecture Controls define the enduring architectural outcomes that must exist regardless of technology, implementation approach, or regulatory change.
Architecture Controls serve as the bridge between business needs, regulatory requirements, and technical implementation. Multiple regulations, policies, standards, patterns, and products may map to the same Architecture Control. This allows the University to maintain a stable architecture framework even as technologies, regulations, and implementation approaches evolve.
Architecture Controls are not regulations, policies, standards, products, or implementation requirements. They define the architectural outcomes that solutions must achieve.
Architecture Controls
1. Data Classification and Regulatory Scope
Data must be identified, classified, inventoried, owned, and associated with applicable regulatory, contractual, research, and business requirements.
2. Identity and Authentication
Users, services, devices, applications, and automated systems must be uniquely identifiable and authenticated.
3. Authorization and Access Management
Access to systems, services, and data must be granted, reviewed, modified, and revoked according to approved business purpose and least privilege.
4. Data Protection
Data must be protected against unauthorized disclosure, modification, destruction, and loss throughout its lifecycle.
5. Boundary Protection and Isolation
Security, operational, and regulatory boundaries must be established and maintained to appropriately separate systems, services, workloads, and data.
6. Asset and Configuration Management
Technology assets, software, services, models, dependencies, and configurations must be identified, managed, maintained, and governed throughout their lifecycle.
7. Interoperability and Information Exchange
Information must be exchanged through defined, governed, secure, supportable, and interoperable interfaces.
8. Monitoring, Logging, and Auditability
Material activities affecting systems, services, data, and automated processes must be observable, attributable, auditable, and reviewable.
9. Resilience and Recovery
Systems, services, and data must be recoverable in accordance with defined continuity, recovery, and availability requirements.
10. Data Lifecycle and Records Management
Data and records must be retained, archived, recovered, disclosed, and disposed of according to approved requirements.
11. Governance and Oversight
Ownership, stewardship, responsibilities, decision authority, and oversight must be defined, assigned, and maintained throughout the lifecycle.
12. Risk and Compliance Management
Risks, compliance obligations, exceptions, compensating controls, and control effectiveness must be identified, assessed, managed, documented, and reviewed.
Desired Outcome
The Architecture Controls provide a stable architectural foundation that enables consistent decision making, regulatory traceability, technology governance, and reusable implementation approaches across the University.