Governance artifact

Architecture Risk Register

Risks are tracked with a mitigation, a residual rating after that mitigation, and a named owning team. Owners below are synthetic organizational functions created for this portfolio.

Application TeamCloud OperationsIdentity TeamPlatform EngineeringSecurity Engineering

Synthetic data

Risk register

Architecture risk register
Risk IDScenarioLikelihoodImpactAffected componentMitigationResidual riskOwnerCase study
RSK-01Migration cutover exceeds the maintenance window and leaves data in an inconsistent state.MediumHighData tier / cutover processTwo full rehearsals with timed rollback, and a documented go/no-go checkpoint.LowCloud OperationsSecure Cloud Migration
RSK-02Over-permissive security-group rules copied from the legacy flat network allow lateral movement.MediumHighNetwork segmentationLeast-privilege rule baseline, flow-log review, and rule tightening in the hardening phase.MediumSecurity EngineeringSecure Cloud Migration
RSK-03Cloud spend exceeds forecast after multi-zone redundancy and log retention are enabled.HighMediumCost governanceMandatory tagging, per-environment budgets, anomaly alerts, and a right-sizing review in Phase 6.MediumPlatform EngineeringSecure Cloud Migration
RSK-04Legacy credentials remain in configuration files after migration and are never rotated.MediumHighSecrets managementPipeline secret scanning plus a hardening-phase task to rotate every migrated credential.LowSecurity EngineeringSecure Cloud Migration
RSK-05Identity provider outage prevents workforce access to all federated applications.LowHighIdentity providerDocumented degraded-access procedure, governed break-glass accounts, and illustrative quarterly drills.MediumIdentity TeamZero-Trust Enterprise Access
RSK-06Conditional access policy misconfiguration locks out a business unit during rollout.MediumMediumPolicy / access layerReport-only rollout, staged enforcement rings, and an emergency policy-revert runbook.LowIdentity TeamZero-Trust Enterprise Access
RSK-07Contractor entitlements persist after project completion because sponsor records are not updated.HighMediumAccess lifecycleTime-boxed entitlements that expire by default, plus illustrative quarterly recertification with named approvers.LowIdentity TeamZero-Trust Enterprise Access
RSK-08Break-glass account credentials are used without detection or post-use review.LowHighPrivileged accessSealed credentials, high-severity alert on any use, mandatory post-use review and rotation.LowSecurity EngineeringZero-Trust Enterprise Access
RSK-09Zone failure exceeds remaining capacity and the surviving zone degrades under load.MediumHighApplication tier capacityMaintain the illustrative 40% headroom sizing assumption, autoscale ahead of saturation, and validate in zone-failure game days.MediumPlatform EngineeringResilient Data & Application Platform
RSK-10Cross-region replication lag exceeds the stated recovery point before a regional failure.MediumHighCross-region replicaAlert on replication lag thresholds and treat sustained lag as an incident, not a warning.MediumCloud OperationsResilient Data & Application Platform
RSK-11Backups complete but restores fail due to undetected corruption or missing keys.LowHighBackup vault / key managementMonthly timed restore tests including key availability in the recovery region.LowCloud OperationsResilient Data & Application Platform
RSK-12Degradation flags left enabled after an incident silently disable customer features.MediumMediumFeature flag serviceFlag state on the operations dashboard, automatic expiry, and a post-incident checklist item.LowApplication TeamResilient Data & Application Platform
RSK-13Alert noise causes on-call responders to miss a genuine customer-impacting failure.MediumHighAlerting & observabilityPage only on customer-impact signals; route symptom alerts to dashboards and weekly review.MediumCloud OperationsResilient Data & Application Platform
RSK-14Workload token issuance failure blocks service-to-service authentication across the platform.LowHighWorkload identityCredential caching with graceful expiry handling and issuance-health alerting.MediumPlatform EngineeringZero-Trust Enterprise Access
RSK-15Application team bypasses the deployment pipeline to make an emergency production change.MediumMediumCI/CD & change controlEmergency-change path with just-in-time elevation, automatic logging, and retrospective review.LowApplication TeamSecure Cloud Migration

Accountability

Risks by owning team

Application Team

  • RSK-12 Degradation flags left enabled after an incident silently disable customer features.
  • RSK-15 Application team bypasses the deployment pipeline to make an emergency production change.

Cloud Operations

  • RSK-01 Migration cutover exceeds the maintenance window and leaves data in an inconsistent state.
  • RSK-10 Cross-region replication lag exceeds the stated recovery point before a regional failure.
  • RSK-11 Backups complete but restores fail due to undetected corruption or missing keys.
  • RSK-13 Alert noise causes on-call responders to miss a genuine customer-impacting failure.

Identity Team

  • RSK-05 Identity provider outage prevents workforce access to all federated applications.
  • RSK-06 Conditional access policy misconfiguration locks out a business unit during rollout.
  • RSK-07 Contractor entitlements persist after project completion because sponsor records are not updated.

Platform Engineering

  • RSK-03 Cloud spend exceeds forecast after multi-zone redundancy and log retention are enabled.
  • RSK-09 Zone failure exceeds remaining capacity and the surviving zone degrades under load.
  • RSK-14 Workload token issuance failure blocks service-to-service authentication across the platform.

Security Engineering

  • RSK-02 Over-permissive security-group rules copied from the legacy flat network allow lateral movement.
  • RSK-04 Legacy credentials remain in configuration files after migration and are never rotated.
  • RSK-08 Break-glass account credentials are used without detection or post-use review.