Capability domain

Security

Establish the trust, resilience, and control required to transform safely as technology becomes more connected, intelligent, and autonomous.

01 — Domain thesis

Security enables transformation by establishing the trust, resilience, and control required to change safely.

Security is not a constraint added after transformation. It is the trust and resilience system that allows transformation to operate at enterprise scale by connecting business outcomes, accountable capabilities, architecture, controls, assurance, intelligence, and recovery.

02 — Transformation questions

Questions the enterprise should be able to answer.

These questions define the capability—not an intake process.

  1. 01Which business outcomes and enterprise capabilities require the greatest protection?
  2. 02Who owns security risk and control effectiveness?
  3. 03How are human, workload, service, and agent identities governed?
  4. 04Where are sensitive information and critical systems exposed?
  5. 05Which controls are preventive, detective, responsive, or recovery-oriented?
  6. 06How is control effectiveness demonstrated rather than assumed?
  7. 07How quickly can the enterprise detect, contain, recover, and learn?
  8. 08How do controls change as AI systems gain access to data, tools, and enterprise actions?
  9. 09How are emerging risks incorporated without destabilizing delivery?

03 — Capability model

Security as an enterprise capability

A reusable lens for understanding the disciplines that must operate together.

Governance, Risk & Assurance

Risk ownership, policies, standards, oversight, compliance, assurance, and executive visibility.

Identity & Access

Human, workload, service, machine, and agent identity; authentication, authorization, privilege, and access governance.

Data Protection

Classification, access, encryption, privacy, leakage prevention, retention, provenance, and data boundaries.

Platform & Infrastructure Security

Cloud, endpoint, network, runtime, application, API, software supply-chain, and infrastructure controls.

Detection & Observability

Telemetry, monitoring, logging, anomaly and threat detection, and operational visibility.

Response & Resilience

Containment, incident response, recovery, continuity, crisis management, and operational resilience.

Security Intelligence

Threat intelligence, control effectiveness, risk signals, metrics, and emerging-risk awareness.

04 — Evolution & maturity

From fragmented practice to intentional enterprise capability

Maturity is visible in how decisions, evidence, controls, and operating behavior become connected.

  1. 01

    Reactive

    Controls and response remain fragmented, event-driven, and weakly connected to business priorities.

  2. 02

    Controlled

    Baseline policies, ownership, architecture, and control expectations become explicit.

  3. 03

    Integrated

    Risk, identity, data, platforms, detection, response, and delivery share evidence and accountability.

  4. 04

    Adaptive

    Continuous assurance and security intelligence revise controls as technology and threats change.

  5. 05

    Resilient

    The enterprise anticipates disruption, contains impact, recovers deliberately, and learns across the operating model.

06 — Frameworks & artifacts

Security operating model

Security defines and verifies the trust boundaries that allow transformation to proceed without unmanaged exposure.

Inputs

  • Threat and risk context
  • Architecture and data flows
  • Identity and regulatory requirements

Decisions

  • Trust boundaries
  • Control placement
  • Residual-risk acceptance

Outputs

  • Security architectures
  • Control requirements
  • Assurance evidence
The Enterprise Security Framework connects business security outcomes to the operating model, enterprise security platform, specialized frameworks, implementation and assurance practices, and a continuously evolving security intelligence capability.
View full-size framework ↗ (opens in a new tab)

Enterprise Security Framework

Enterprise Security Framework showing business security outcomes, an eight-capability security operating model, enterprise security platform capabilities, specialized security frameworks, implementation and assurance practices, security intelligence, cross-cutting themes, and foundational principles.

Applied in Practice

Mapspring

Authorization hardening, PostgreSQL row-level security, a least-privilege public-data boundary, and executable security contracts.

See Mapspring in practice

Framework and Lab boundary

Frameworks define the model. Labs test implementations.

The Security domain defines enterprise trust, resilience, and assurance. Labs test emerging agentic risks and controls including non-human identity, prompt injection, tool authorization, data boundaries, observation, interruption, escalation, and containment.

07 — Labs & experiments

Applied exploration

Current exploration

Agentic Security

Current exploration of agent identity, authorization, tool permissions, data boundaries, prompt injection, observability, containment, escalation, and human control.

Explore

08 — Insights & related work

Published learning

Published

Agentic AI Security & Controls

An executive and architectural view of controlling what agents can know, decide, access, and do.

Explore