Skip to content

Security Architecture

What is Security Architecture?

The design artefacts that describe how security controls are positioned and relate to the overall IT architecture. Security architecture provides a structured approach to designing, implementing, and maintaining security across an organisation.

Information Security

Each of these is named in at least one of the same controls as security architecture. The number is how many controls name both.

What the standards actually require on security architecture

Requirements naming security architecture across 6 standards, quoted from the control text.

Define the overall 5G security architecture covering UE, RAN, core network, and service-based interfaces with documented trust boundaries.

TS33.501-4.1 · 5G Security Architecture Overview

Apply defence in depth across power system zones with documented architecture and trust boundaries.

IEC62351-10 · Security Architecture

ITU-T Recommendation X.805 (10/2003) Security architecture for systems providing end-to-end communications is a foundational network security architecture standard published by the International Telecommunication Union Telecommunication Standardization Sector...

X805-Scope-Architecture-3Layers-3Planes-8Dimensions-5Threats-72Cells-X.800-Series-Heritage · ITU-T X.805 Scope + Security Architecture Overview + 3 Security Layers x 3 Security Planes (9 Modules) x 8 Security Dimensions = 72 Security Perspectives + 5 Threat Categories + X.800-Series Heritage + End-to-End Network Communications

A system's security architecture is approved prior to the development of the system.

ISM-1739 · A system's security architecture is approved prior to the development of the system.

Implement layered security architecture: perimeter security, firewalls between zones, unidirectional gateways/diodes where appropriate, access and authentication controls, and restrictions on bring-your-own-device.

CISA-ICS-DID-25 · Security Architecture (Perimeter, Firewalls, Diodes, Access)

FAA Advisory Circular 25-21 establishes the cybersecurity architecture framework for transport-category aircraft (14 CFR Part 25) covering: (a) aircraft information system domain (AISD) architecture - the cabin systems + IFE + airline operations systems isolat...

FAA-CSA-AC25-21 · Aircraft Network Security Architecture (FAA AC 25-21) - the AISD onboard-network framework

Questions people ask about security architecture

What is Security Architecture?
The design artefacts that describe how security controls are positioned and relate to the overall IT architecture. Security architecture provides a structured approach to designing, implementing, and maintaining security across an organisation.
Why is Security Architecture important for compliance?
Security Architecture is a key concept in Information Security. Understanding security architecture helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Security Architecture?
Security Architecture appears in the requirement text of 3GPP 5G Security Architecture (TS 33.501), IEC 62351 - Power Systems Communication Security, ITU-T X.805 - Security Architecture for End-to-End Communications, Australian Information Security Manual, CISA Industrial Control Systems (ICS) Security Guidance. Across these standards we have identified 9 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Security Architecture?
Explore our compliance framework pages to see how security architecture applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Security Architecture applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.