ALVOR
Platform
Advisory
PricingBlog
Get Demo
ALVOR
Platform
Advisory
PricingBlog
Get Demo

Learn

Security architecture, risk and compliance, explained properly.

Each guide defines one term, shows how it works step by step with a worked example, names the standards behind it, and ends with how Alvor helps. Written by practitioners for anyone who has to do the work.

Security architecture

What is enterprise security architecture?

Enterprise security architecture is security architecture practised across a whole organisation rather than one system. It sets what individual designs inherit: the business attributes security has to protect, the domains and the trust relationships between them, the patterns and standards teams build to, and the governance that checks a design before it ships. Its test is traceability, from a business objective down to a control and back.

Read the guide · 20 min read

What is security architecture?

Security architecture is the practice of deciding how a system will resist attack and keep working, and recording those decisions so they can be reviewed, built to and audited. It is structural work: security domains and the trust relationships between them, where data flows and crosses a boundary, which controls sit at each crossing, and who is accountable. NIST calls the result security-relevant views of a system's architecture.

Read the guide · 23 min read

Secure by Design and threat modeling

What is a data flow diagram in threat modeling?

A data flow diagram is a map of how data moves through a system, drawn so a team can ask what could go wrong. It uses five element types: external entities, processes, data stores, data flows and trust boundaries. Every flow that crosses a trust boundary is a place where trust changes, so that is where attacks land and where controls belong.

Read the guide · 20 min read

Risk and compliance

What is a risk register?

A risk register is the record of the risks an organisation has identified, what it decided about each one, and who decided. Each entry carries a description, an owner, an assessment of likelihood and impact, the response chosen, and a status. NIST's published template adds a priority and an exposure rating. Its value is the decisions it holds, not the list.

Read the guide · 22 min read

What is GRC (governance, risk and compliance)?

GRC stands for governance, risk and compliance: the way an organisation sets its own rules, decides what could stop it keeping them, and proves to outsiders that it does. OCEG defines it as the integrated collection of capabilities that let an organisation reliably achieve objectives, address uncertainty and act with integrity. In practice it names four records: controls, risks, policies and evidence.

Read the guide · 20 min read

Australia

What is APRA CPS 230?

APRA Prudential Standard CPS 230 Operational Risk Management is the Australian prudential rule that requires banks, insurers and superannuation trustees to manage operational risk, keep critical operations running within stated tolerance levels through severe disruptions, and manage the risks of the service providers they rely on. The current version commenced on 1 July 2026 and replaced five older standards.

Read the guide · 20 min read
ALVOR

Security architecture management and compliance: connected into one source of truth.

Security,
Simplified.

Platform

  • Overview
  • AI Assistant
  • Secure by Design
  • Asset Management
  • Risk Management
  • Compliance
  • Policy
  • Security Management
  • Third-Party Risk Management
  • Business Continuity

Capabilities

  • Security Architecture
  • Security Design Review
  • Threat Modeling
  • Dependency Mapping
  • Data Governance
  • Components & SBOM
  • System Security Plan
  • Deployment models

Solutions

  • All solutions
  • CISO
  • Security architect
  • GRC lead
  • Engineering leader
  • Startups
  • Mid-Market
  • Enterprise
  • Regulated & Sovereign
  • Australia

Frameworks

  • ISO 27001
  • SOC 2
  • NIST CSF
  • HIPAA
  • GDPR
  • ISM
  • IRAP
  • Essential Eight
  • ASD Essentials
  • SABSA
  • PCI DSS
  • CMMC
  • FedRAMP
  • Control alignment

Advisory

  • Advisory overview
  • Assess
  • Architect
  • Build
  • Operate
  • All engagements

Company

  • About
  • Blog
  • Learn
  • Security
  • Pricing
  • Compare Alvor

© 2026 Alvor Pty Ltd · ABN 40 700 022 546 · All rights reserved.

PrivacyTermsCookie PolicyVulnerability Disclosure