Jason Edwards
This chapter explains how defensive security architecture becomes effective when it is built as layered, independent controls that assume failure and limit blast radius. It shows how trust boundaries and policy enforcement points create predictable control placement across identity, endpoint, network, and data. The focus is on turning architectural intent into practical outcomes: preventing implicit trust paths, improving observability, and ensuring detection and containment still function when any single control is bypassed. It then demonstrates how to translate risk into concrete architecture decisions by expressing risk as operational scenarios and design questions. The discussion emphasizes enforceable patterns that teams can reuse and validate to reduce drift, speed delivery, and avoid bespoke implementations that are difficult to defend. It also addresses operational constraints like legacy dependencies, change velocity, and cross-team handoffs, highlighting how architecture must be measurable in production rather than correct only in diagrams. Finally, the chapter covers resilience and recovery thinking as core design requirements, including safe degradation, rapid containment levers, and reduced time to truth during incidents. It frames AI in architecture as both an automation opportunity and a new attack surface, requiring strong telemetry inputs, human-in-the-loop approval boundaries, and auditability to manage failure modes such as drift and false confidence. The chapter closes by showing how standards and exceptions should be documented as living artifacts and kept aligned with business change so the environment remains defensible as technology and operations evolve.