Architecture Glossary

Purpose

This glossary defines common terminology used throughout the Enterprise Architecture Framework, Architecture Controls, Policies, Standards, Architecture Decision Records (ADRs), Patterns, Products, and implementation documentation.

Where a term is governed by a University policy, the applicable policy number is identified in the Policy Dependency field. Definitions linked to policies should be reviewed whenever the referenced policy changes.

A

Access Control

Definition: The processes, mechanisms, and technologies used to grant, restrict, review, modify, and revoke access to systems, services, applications, and data.

Policy Dependency: 946.0 Privileged Access to Sensitive University Data and Data Systems


Application Identity

Definition: A non-human identity used by an application to authenticate and access services, resources, APIs, or data.

Policy Dependency: None


Architecture Decision Record (ADR)

Definition: A document that records a significant architecture decision, the rationale for that decision, and the consequences of adopting it.

Policy Dependency: None


Architecture Pattern

Definition: An approved implementation approach used to consistently satisfy architecture requirements and standards.

Policy Dependency: None


Audit Log

Definition: A record of activities, events, actions, changes, or access that supports operational review, investigations, compliance, and accountability.

Policy Dependency: 285.1 Cybersecurity


Authentication

Definition: The process of verifying the identity of a user, service, application, or system.

Policy Dependency: 946.0 Privileged Access to Sensitive University Data and Data Systems


Authorization

Definition: The process of determining what actions an authenticated identity is permitted to perform.

Policy Dependency: 946.0 Privileged Access to Sensitive University Data and Data Systems


D

Data Classification

Definition: The process of identifying and categorizing data according to its sensitivity, regulatory requirements, contractual obligations, institutional requirements, and business value.

Policy Dependency: 921.0 Data Classification


Data Classification Level

Definition: A designation assigned to data that identifies the level of protection, handling requirements, access restrictions, and governance controls that must be applied throughout the data lifecycle. 

Policy Dependency: 921.0 Data Classification


Data Disposal

Definition: The approved process for permanently removing or destroying data that is no longer required.

Policy Dependency: 924.0 Data Disposal


Data Protection

Definition: The safeguards and controls used to maintain the confidentiality, integrity, availability, recoverability, and accountability of data throughout its lifecycle.

Policy Dependency: 922.0 Data Management, Use and Protection


E

Encryption at Rest

Definition: Protection of stored data through approved encryption mechanisms while data resides on storage media.

Policy Dependency: 922.0 Data Management, Use and Protection


Encryption in Transit

Definition: Protection of data through approved encrypted communication methods while data is transmitted between systems, services, applications, or networks.

Policy Dependency: 922.0 Data Management, Use and Protection


Enterprise Identity Service

Definition: An approved centralized identity platform used as the authoritative source for authentication and authorization.

Policy Dependency: None


Enterprise Workload

Definition: A workload operating under the enterprise control baseline and approved to process Public, Sensitive/Internal, Highly Sensitive, and authorized Restricted data classifications. 

Policy Dependency: None


G

Governance

Definition: The processes, controls, oversight mechanisms, standards, and decision authorities used to manage technology environments consistently and accountably.

Policy Dependency: 285.1 Cybersecurity


Governance Boundary

Definition: A designated scope within which governance controls, policies, standards, monitoring requirements, and compliance obligations are applied and enforced. 

Policy Dependency: None


Governance Inheritance

Definition: The application of governance controls through hierarchical assignment such that subordinate resources inherit required governance, security, compliance, and operational controls.

Policy Dependency: None


H

HIPAA Workload

Definition: A regulated workload that creates, stores, processes, transmits, or provides access to Protected Health Information (PHI).

Policy Dependency: None


I

Identity Governance

Definition: The processes used to provision, modify, review, and remove access throughout the identity lifecycle.

Policy Dependency: 946.0 Privileged Access to Sensitive University Data and Data Systems


Incident Investigation

Definition: Activities performed to understand, analyze, document, and respond to operational or security events.

Policy Dependency: 911.0 Data Security Incident Response


Innovation Workload

Definition: A workload supporting experimentation, research, evalutation, proofs of concept, or emerging technologies. Innovation workloads may process Public and Sensitive/Internal data, but shall not process Highly Sensitive or Restricted data. 

Policy Dependency: None


L

Least Privilege

Definition: The principle that users, services, and systems receive only the permissions necessary to perform approved business functions.

Policy Dependency: 946.0 Privileged Access to Sensitive University Data and Data Systems


Logging

Definition: The collection and retention of records relating to system activity, security events, operational actions, and administrative actions.

Policy Dependency: 285.1 Cybersecurity


M

Monitoring

Definition: The collection, analysis, and use of operational, security, audit, and platform telemetry to support visibility, operations, investigations, and compliance activities.

Policy Dependency: 285.1 Cybersecurity


O

Operational Continuity

Definition: The capability of a workload to continue or resume operations during and after disruptions, failures, or recovery activities.

Policy Dependency: 925.0 Backup and Recovery Systems


P

Protected Health Information (PHI)

Definition: Individually identifiable health information protected under the Health Insurance Portability and Accountability Act (HIPAA) and associated regulations.

Policy Dependency: None


Privileged Access

Definition: Administrative or elevated access that permits management, configuration, or control of systems, services, applications, or data.

Policy Dependency: 946.0 Privileged Access to Sensitive University Data and Data Systems


R

Recovery

Definition: The restoration of systems, applications, services, or data following a failure, disruption, corruption event, or disaster.

Policy Dependency: 925.0 Backup and Recovery Systems


Regulated Data

Definition: Data subject to legal, regulatory, contractual, research, licensing, grant or institutional requirements governing its use, disclosure, transmission, storage, retention, protection, or disposal. 

Policy Dependency: 922.0 Data Management, Use and Protection


Regulated Workload

Definition: A workload requiring enhanced governance, security, monitoring, auditability, recovery, or compliance controls due to regulatory, contractual, legal, or institutional requirements.

Policy Dependency: None


Role-Based Access Control (RBAC)

Definition: An authorization model that assigns access permissions through defined roles rather than direct assignment to individuals.

Policy Dependency: 946.0 Privileged Access to Sensitive University Data and Data Systems


S

Service Identity

Definition: A non-human identity used by applications, automation, integrations, and platform services for authentication and resource access.

Policy Dependency: None


Shared Service

Definition: A centrally managed platform capability that can support multiple workloads while maintaining workload isolation and governance requirements.

Policy Dependency: None


W

Workload

Definition: A collection of applications, services, databases, integrations, infrastructure components, and supporting capabilities that together deliver a business or technical function.

Policy Dependency: None


Workload Isolation

Definition: The deployment of workloads into dedicated cloud governance, administrative, operational, and security boundaries appropriate for business, regulatory, and operational requirements.

Policy Dependency: None