← Architect · Master

Knowledge material · ~6 min read

Architect · Master

You can architect a client end-to-end and defend the design.

Overview

Master Architects own the why. You apply the Well-Architected pillars, threat-model with STRIDE, decode compliance frameworks into engineering work, and instrument systems so the next outage tells you what happened before customers do.

Well-Architected pillars

  • ▸Operational excellence — run + improve.
  • ▸Security — protect data, identity, workloads.
  • ▸Reliability — survive failure.
  • ▸Performance efficiency — right resources, right time.
  • ▸Cost optimization — pay for value.
  • ▸Sustainability — efficient by design.

Threat modeling with STRIDE

  • ▸Spoofing — identity attacks → authN.
  • ▸Tampering — integrity → signing, checksums.
  • ▸Repudiation → logging, non-repudiation.
  • ▸Information disclosure → encryption, least privilege.
  • ▸Denial of Service → rate limit, scale.
  • ▸Elevation of Privilege → segregation, RBAC (Role-Based Access Control).

Compliance decoded

  • ▸SOC (Security Operations Center) 2 — service-org controls; trust services criteria.
  • ▸ISO (International Organization for Standardization) 27001 — ISMS, risk-based.
  • ▸HIPAA (Health Insurance Portability and Accountability Act) — PHI (Protected Health Information) safeguards (admin/physical/technical).
  • ▸PCI (Payment Card Industry) DSS — cardholder data scope reduction is the game.
  • ▸NIST (National Institute of Standards and Technology) CSF (Cybersecurity Framework) / CIS (Center for Internet Security) Controls — implementation roadmaps.

Observability (the three pillars)

  • ▸Metrics — numeric time series; cheap, aggregable.
  • ▸Logs — text events; expensive, searchable.
  • ▸Traces — request paths across services.
  • ▸SLI (Service Level Indicator)/SLO (Service Level Objective)/SLA (Service Level Agreement) — what you measure, what you commit, what you contract.

Glossary

STRIDE
Threat categories used in design-time threat modeling.
SLI/SLO/SLA
Indicator (measured), Objective (internal), Agreement (external).
ISMS
Information Security Management System — the ISO 27001 program.
PHI
Protected Health Information — HIPAA's regulated data class.

Common pitfalls

Practice drills