Captures significant architecture decisions, rationale, consequences, and governance considerations to provide traceability and support consistent decision-making.
The University of Arkansas will use Azure Commercial as the hosting environment for regulated workloads, including HIPAA workloads, when required security, governance, and compliance controls can be implemented using approved architecture patterns and standards.
Azure Government will not be the default hosting environment. Exceptions may be evaluated when regulatory, contractual, or institutional requirements explicitly require a government cloud environment.
Defines Enterprise, Innovation, and Regulated as the University's cloud operating domains. Operating domains establish governance inheritance and approved implementation flexibility while remaining independent of data classification and regulatory scope.
The University of Arkansas will use centralized enterprise identity services as the authoritative identity provider for Regulated data workloads hosted in Azure.
Authentication, authorization, privileged access, and workload identities will be managed through approved enterprise identity services and implemented through standardized identity patterns.
The University of Arkansas will use Azure Management Groups as the primary governance boundary for cloud environments.
Security, compliance, operational, and platform controls will be applied through Management Group inheritance rather than direct configuration of individual subscriptions whenever practical.
Defines the University cloud delivery model. Cloud services are delivered as consumable products composed of reusable modules. Products represent offerings requested by consumers, while modules represent implementation components used to construct products.
The University of Arkansas will permit approved shared platform services to support HIPAA workloads when those services do not process, store, or expose protected health information (PHI).
Shared services may be consumed by regulated workloads when they satisfy approved security, governance, and operational requirements.
The University of Arkansas will use subscription-level isolation as the primary boundary for regulated workloads hosted in Azure.
Workloads requiring HIPAA controls will be deployed into dedicated subscriptions governed through approved standards, architecture patterns, and policy assignments rather than sharing a common multi-tenant regulated environment.