Governance, Risk & Assurance
Risk ownership, policies, standards, oversight, compliance, assurance, and executive visibility.
Capability domain
Establish the trust, resilience, and control required to transform safely as technology becomes more connected, intelligent, and autonomous.
01 — Domain thesis
Security is not a constraint added after transformation. It is the trust and resilience system that allows transformation to operate at enterprise scale by connecting business outcomes, accountable capabilities, architecture, controls, assurance, intelligence, and recovery.
02 — Transformation questions
These questions define the capability—not an intake process.
03 — Capability model
A reusable lens for understanding the disciplines that must operate together.
Risk ownership, policies, standards, oversight, compliance, assurance, and executive visibility.
Human, workload, service, machine, and agent identity; authentication, authorization, privilege, and access governance.
Classification, access, encryption, privacy, leakage prevention, retention, provenance, and data boundaries.
Cloud, endpoint, network, runtime, application, API, software supply-chain, and infrastructure controls.
Telemetry, monitoring, logging, anomaly and threat detection, and operational visibility.
Containment, incident response, recovery, continuity, crisis management, and operational resilience.
Threat intelligence, control effectiveness, risk signals, metrics, and emerging-risk awareness.
04 — Evolution & maturity
Maturity is visible in how decisions, evidence, controls, and operating behavior become connected.
Controls and response remain fragmented, event-driven, and weakly connected to business priorities.
Baseline policies, ownership, architecture, and control expectations become explicit.
Risk, identity, data, platforms, detection, response, and delivery share evidence and accountability.
Continuous assurance and security intelligence revise controls as technology and threats change.
The enterprise anticipates disruption, contains impact, recovers deliberately, and learns across the operating model.
05 — Connections
Security establishes trust and resilience. People & Change redesigns work and organizational capability. Execution turns intent into working systems and measurable outcomes.
Connects risk appetite and resilience to strategic choices.
Explore domainDefines risk ownership, oversight, policy, accountability, and assurance.
Explore domainEmbeds identity, controls, resilience, and observability into the target state.
Explore domainProtects sensitive information and establishes appropriate access boundaries.
Explore domainControls model, agent, tool, data, and system access as autonomy increases.
Explore domainShapes accountable behavior, awareness, access discipline, and human-machine operating practices.
Explore domainIntegrates security into engineering, DevSecOps, reliability, assurance, and operational readiness.
Explore domain06 — Frameworks & artifacts
Security defines and verifies the trust boundaries that allow transformation to proceed without unmanaged exposure.
Applied in Practice
Authorization hardening, PostgreSQL row-level security, a least-privilege public-data boundary, and executable security contracts.
See Mapspring in practiceFramework and Lab boundary
The Security domain defines enterprise trust, resilience, and assurance. Labs test emerging agentic risks and controls including non-human identity, prompt injection, tool authorization, data boundaries, observation, interruption, escalation, and containment.
07 — Labs & experiments
Current exploration
Current exploration of agent identity, authorization, tool permissions, data boundaries, prompt injection, observability, containment, escalation, and human control.
Explore08 — Insights & related work
Published
An executive and architectural view of controlling what agents can know, decide, access, and do.
ExploreExplore related work
Security is not a constraint added after transformation. It is the trust and resilience system that allows transformation to operate at enterprise scale.
Framework
An integrated operating model connecting business outcomes, security leadership, architecture, controls, assurance, and intelligence.
ExploreFramework
A six-phase process for discovering, assessing, designing, building, operating, and evolving transformation.
ExploreLab
Current exploration of agent identity, authorization, tool permissions, data boundaries, prompt injection, observability, containment, escalation, and human control.
ExploreInsight
An executive and architectural view of controlling what agents can know, decide, access, and do.
Explore