Part II — Technical Foundations of Architecture Chapter 9

Security as Architecture

Security is not a feature to add at the end. This chapter covers threat modeling, the principle of least privilege applied at the system level, zero trust architecture, and how to make security a first-class architectural concern.

What this chapter covers
  • Threat modeling with STRIDE
  • Zero trust architecture principles
  • Principle of least privilege at system scale
  • OAuth 2.0 and OpenID Connect architecture
  • Role-based and attribute-based access control (RBAC/ABAC)
  • Secrets management and key rotation
  • Secure-by-design vs. security-as-afterthought
  • Security architecture review process

Read Chapter 9 in Full

Available on LeanPub (PDF, ePub, MOBI) and Amazon (Kindle and Paperback).