Articles (19)

Pinned Article DRAFT: Enterprise Architecture Framework

The Enterprise Architecture Framework provides a common way to connect business needs, regulatory requirements, architecture decisions, implementation standards, approved patterns, infrastructure products, and deployed solutions. It helps teams make consistent, supportable, and traceable technology decisions throughout the lifecycle of a solution. Supported by the architecture ecosystem represented by the current ADRs, standards, patterns, governance model, and implementation approach.

DRAFT: ADR Azure Commercial for Regulated Workloads

The University of Arkansas will use Azure Commercial as the hosting environment for regulated workloads, including HIPAA workloads, when required security, governance, and compliance controls can be implemented using approved architecture patterns and standards.

Azure Government will not be the default hosting environment. Exceptions may be evaluated when regulatory, contractual, or institutional requirements explicitly require a government cloud environment.

DRAFT: ADR HIPAA Identity Model

The University of Arkansas will use centralized enterprise identity services as the authoritative identity provider for HIPAA workloads hosted in Azure.

Authentication, authorization, privileged access, and workload identities will be managed through approved enterprise identity services and implemented through standardized identity patterns.

DRAFT: ADR Management Group Governance Model

The University of Arkansas will use Azure Management Groups as the primary governance boundary for cloud environments.

Security, compliance, operational, and platform controls will be applied through Management Group inheritance rather than direct configuration of individual subscriptions whenever practical.

DRAFT: ADR Shared Services Outside the HIPAA Boundary

The University of Arkansas will permit approved shared platform services to support HIPAA workloads when those services do not process, store, or expose protected health information (PHI).

Shared services may be consumed by regulated workloads when they satisfy approved security, governance, and operational requirements.

DRAFT: ADR Subscription-based Isolation Strategy

The University of Arkansas will use subscription-level isolation as the primary boundary for regulated workloads hosted in Azure.

Workloads requiring HIPAA controls will be deployed into dedicated subscriptions governed through approved standards, architecture patterns, and policy assignments rather than sharing a common multi-tenant regulated environment.

DRAFT: Azure Subscription Standard

Defines the requirements for creation, governance, management, ownership, and lifecycle management of Azure subscriptions within University-managed Azure environments, establishing Azure subscriptions as the primary workload isolation, administrative, operational, and accountability boundary for cloud workloads.

DRAFT: Cloud Governance Standard

Defines the governance requirements for Azure environments managed by the University, including Management Group governance, policy inheritance, compliance controls, operational guardrails, resource accountability, and governance enforcement. This standard establishes the governance model used to manage cloud environments consistently across regulated and non-regulated workloads.

DRAFT: Data Protection Pattern

Describes the approved implementation pattern for data protection, encryption, backup, recovery, retention, and data lifecycle management for HIPAA workloads hosted within University-managed Azure environments.

DRAFT: Enterprise Architecture Principles

Defines the enduring principles that guide technology strategy, architecture decisions, governance, engineering, and operations across the University. These principles provide a common foundation for developing Architecture Controls, Architecture Decision Records, Standards, Patterns, Products, and technology implementations while promoting alignment, security, reuse, visibility, resilience, supportability, and continuous improvement.

DRAFT: HIPAA Contingency and Resiliency Pattern

Describes the approved implementation pattern for workload resiliency, operational continuity, backup, recovery, restoration, and service availability for HIPAA workloads hosted within University-managed Azure environments.

DRAFT: HIPAA Data Protection Standard

Defines the requirements for protecting Protected Health Information (PHI) and other regulated data within University-managed Azure environments through approved controls for encryption, backup, recovery, retention, resiliency, and access protection.

DRAFT: HIPAA Hosting Standard

Defines the minimum requirements for hosting HIPAA workloads in University-managed Azure environments.

DRAFT: HIPAA Identity Pattern

Describes the approved implementation pattern for identity and access management for HIPAA workloads hosted in University-managed Azure environments.

DRAFT: HIPAA Monitoring Pattern

Describes the approved implementation pattern for monitoring, logging, alerting, and audit visibility for HIPAA workloads hosted in University-managed Azure environments.

DRAFT: HIPAA Monitoring Standard

Defines the monitoring, logging, auditing, alerting, and operational visibility requirements for HIPAA workloads hosted in University-managed Azure environments.

DRAFT: HIPAA Network Pattern

Describes the approved implementation pattern for networking and connectivity for HIPAA workloads hosted in University-managed Azure environments.

DRAFT: HIPAA Network Standard

Defines the networking, connectivity, segmentation, boundary protection, traffic management, and network governance requirements for HIPAA workloads hosted within University-managed Azure environments.

DRAFT: HIPAA Shared Services Pattern

Describes the approved implementation pattern for using enterprise shared services to support HIPAA workloads hosted within University-managed Azure environments while maintaining workload isolation, governance requirements, security controls, and regulatory boundaries.