DRAFT: Architecture Controls

Summary

Defines the Architecture Controls that serve as the enduring architectural outcomes connecting business needs, regulatory requirements, policies, standards, decisions, patterns, products, and implementations within the Enterprise Architecture Framework.

Body

Purpose

Architecture Controls define the enduring architectural outcomes that must exist regardless of technology, implementation approach, or regulatory change.

Architecture Controls serve as the bridge between business needs, regulatory requirements, and technical implementation. Multiple regulations, policies, standards, patterns, and products may map to the same Architecture Control. This allows the University to maintain a stable architecture framework even as technologies, regulations, and implementation approaches evolve.

Architecture Controls are not regulations, policies, standards, products, or implementation requirements. They define the architectural outcomes that solutions must achieve.

Architecture Controls

1. Data Classification and Regulatory Scope

Data must be identified, classified, inventoried, owned, and associated with applicable regulatory, contractual, research, and business requirements.

2. Identity and Authentication

Users, services, devices, applications, and automated systems must be uniquely identifiable and authenticated.

3. Authorization and Access Management

Access to systems, services, and data must be granted, reviewed, modified, and revoked according to approved business purpose and least privilege.

4. Data Protection

Data must be protected against unauthorized disclosure, modification, destruction, and loss throughout its lifecycle.

5. Boundary Protection and Isolation

Security, operational, and regulatory boundaries must be established and maintained to appropriately separate systems, services, workloads, and data.

6. Asset and Configuration Management

Technology assets, software, services, models, dependencies, and configurations must be identified, managed, maintained, and governed throughout their lifecycle.

7. Interoperability and Information Exchange

Information must be exchanged through defined, governed, secure, supportable, and interoperable interfaces.

8. Monitoring, Logging, and Auditability

Material activities affecting systems, services, data, and automated processes must be observable, attributable, auditable, and reviewable.

9. Resilience and Recovery

Systems, services, and data must be recoverable in accordance with defined continuity, recovery, and availability requirements.

10. Data Lifecycle and Records Management

Data and records must be retained, archived, recovered, disclosed, and disposed of according to approved requirements.

11. Governance and Oversight

Ownership, stewardship, responsibilities, decision authority, and oversight must be defined, assigned, and maintained throughout the lifecycle.

12. Risk and Compliance Management

Risks, compliance obligations, exceptions, compensating controls, and control effectiveness must be identified, assessed, managed, documented, and reviewed.

Desired Outcome

The Architecture Controls provide a stable architectural foundation that enables consistent decision making, regulatory traceability, technology governance, and reusable implementation approaches across the University.

Details

Details

Article ID: 2185
Created
Tue 9/8/26 12:44 AM
Modified
Sat 9/19/26 4:16 PM
Audience
Staff