The architecture review should become more specific as it moves from mission to assets, identities, flows, trust, controls, dependencies, and recovery. Each layer should answer a different professional question.
Mission and service
Review question: Which fictional service outcomes matter most, and what would materially affect users or business operations?
Northbridge: Northbridge Learning Portal availability, trustworthy administrative actions, protected student-service data, reliable reporting, and recoverable service operations.
Evidence: Case charter, service inventory, business-impact notes, ownership records.
Assets and data
Review question: Which applications, identities, services, data stores, queues, configuration states, logs, and recovery assets deserve protection?
Northbridge: Portal application, identity platform, worker service, protected data store, reporting queue, monitoring pipeline, configuration records, and backup/recovery artifacts.
Evidence: Architecture inventory, data-classification notes, service records, recovery inventory.
Identity paths
Review question: Which human and workload identities can act, what resources can they reach, and where does privilege change?
Northbridge: Student users, staff users, privileged administrators, portal workload identity, worker workload identity, monitoring service identity, and recovery operator role.
Evidence: Role inventory, approval records, identity design, access-review notes.
Data and service flows
Review question: What information or requests move between components, and what security expectations apply at each step?
Northbridge: User requests reach the portal, the portal requests identity and data services, worker jobs use queue and storage dependencies, and monitoring sources export evidence to the collector.
Evidence: Architecture diagram, application-flow notes, service dependency map.
Trust boundaries
Review question: Where does control, identity, administrative authority, data sensitivity, environment, or organizational responsibility change?
Northbridge: User-to-portal, portal-to-data, administrator-to-management plane, workload-to-cloud service, provider/customer boundary, and monitoring-source-to-collector relationships.
Evidence: Architecture diagram, role definitions, cloud responsibility notes, policy requirements.
Control expectations
Review question: Which prevention, detection, response, recovery, privacy, and governance controls should exist at important boundaries?
Northbridge: Strong identity, least privilege, scoped service access, audit evidence, source-health monitoring, change governance, recovery validation, and privacy-aware telemetry.
Evidence: Policy, standards, threat model, detection plan, recovery requirements.
Dependencies and concentration
Review question: Which shared services could affect several security or availability outcomes at once?
Northbridge: Identity, monitoring, worker queue, protected storage, configuration, and recovery services create shared dependency relationships.
Evidence: Dependency inventory, service-health records, architecture review.
Recovery and degraded operation
Review question: How should the environment behave when identity, monitoring, queue, or recovery dependencies are partially unavailable?
Northbridge: Critical functions should have bounded degraded behavior, clear ownership, recovery priorities, source-health awareness, and validation before normal confidence returns.
Evidence: Recovery objectives, degraded-mode notes, service-owner decisions, validation records.