Governance artifact
Architecture Risk Register
Risks are tracked with a mitigation, a residual rating after that mitigation, and a named owning team. Owners below are synthetic organizational functions created for this portfolio.
Application TeamCloud OperationsIdentity TeamPlatform EngineeringSecurity Engineering
Synthetic data
Risk register
| Risk ID | Scenario | Likelihood | Impact | Affected component | Mitigation | Residual risk | Owner | Case study |
|---|---|---|---|---|---|---|---|---|
| RSK-01 | Migration cutover exceeds the maintenance window and leaves data in an inconsistent state. | Medium | High | Data tier / cutover process | Two full rehearsals with timed rollback, and a documented go/no-go checkpoint. | Low | Cloud Operations | Secure Cloud Migration |
| RSK-02 | Over-permissive security-group rules copied from the legacy flat network allow lateral movement. | Medium | High | Network segmentation | Least-privilege rule baseline, flow-log review, and rule tightening in the hardening phase. | Medium | Security Engineering | Secure Cloud Migration |
| RSK-03 | Cloud spend exceeds forecast after multi-zone redundancy and log retention are enabled. | High | Medium | Cost governance | Mandatory tagging, per-environment budgets, anomaly alerts, and a right-sizing review in Phase 6. | Medium | Platform Engineering | Secure Cloud Migration |
| RSK-04 | Legacy credentials remain in configuration files after migration and are never rotated. | Medium | High | Secrets management | Pipeline secret scanning plus a hardening-phase task to rotate every migrated credential. | Low | Security Engineering | Secure Cloud Migration |
| RSK-05 | Identity provider outage prevents workforce access to all federated applications. | Low | High | Identity provider | Documented degraded-access procedure, governed break-glass accounts, and illustrative quarterly drills. | Medium | Identity Team | Zero-Trust Enterprise Access |
| RSK-06 | Conditional access policy misconfiguration locks out a business unit during rollout. | Medium | Medium | Policy / access layer | Report-only rollout, staged enforcement rings, and an emergency policy-revert runbook. | Low | Identity Team | Zero-Trust Enterprise Access |
| RSK-07 | Contractor entitlements persist after project completion because sponsor records are not updated. | High | Medium | Access lifecycle | Time-boxed entitlements that expire by default, plus illustrative quarterly recertification with named approvers. | Low | Identity Team | Zero-Trust Enterprise Access |
| RSK-08 | Break-glass account credentials are used without detection or post-use review. | Low | High | Privileged access | Sealed credentials, high-severity alert on any use, mandatory post-use review and rotation. | Low | Security Engineering | Zero-Trust Enterprise Access |
| RSK-09 | Zone failure exceeds remaining capacity and the surviving zone degrades under load. | Medium | High | Application tier capacity | Maintain the illustrative 40% headroom sizing assumption, autoscale ahead of saturation, and validate in zone-failure game days. | Medium | Platform Engineering | Resilient Data & Application Platform |
| RSK-10 | Cross-region replication lag exceeds the stated recovery point before a regional failure. | Medium | High | Cross-region replica | Alert on replication lag thresholds and treat sustained lag as an incident, not a warning. | Medium | Cloud Operations | Resilient Data & Application Platform |
| RSK-11 | Backups complete but restores fail due to undetected corruption or missing keys. | Low | High | Backup vault / key management | Monthly timed restore tests including key availability in the recovery region. | Low | Cloud Operations | Resilient Data & Application Platform |
| RSK-12 | Degradation flags left enabled after an incident silently disable customer features. | Medium | Medium | Feature flag service | Flag state on the operations dashboard, automatic expiry, and a post-incident checklist item. | Low | Application Team | Resilient Data & Application Platform |
| RSK-13 | Alert noise causes on-call responders to miss a genuine customer-impacting failure. | Medium | High | Alerting & observability | Page only on customer-impact signals; route symptom alerts to dashboards and weekly review. | Medium | Cloud Operations | Resilient Data & Application Platform |
| RSK-14 | Workload token issuance failure blocks service-to-service authentication across the platform. | Low | High | Workload identity | Credential caching with graceful expiry handling and issuance-health alerting. | Medium | Platform Engineering | Zero-Trust Enterprise Access |
| RSK-15 | Application team bypasses the deployment pipeline to make an emergency production change. | Medium | Medium | CI/CD & change control | Emergency-change path with just-in-time elevation, automatic logging, and retrospective review. | Low | Application Team | Secure Cloud Migration |
Accountability
Risks by owning team
Application Team
- RSK-12 Degradation flags left enabled after an incident silently disable customer features.
- RSK-15 Application team bypasses the deployment pipeline to make an emergency production change.
Cloud Operations
- RSK-01 Migration cutover exceeds the maintenance window and leaves data in an inconsistent state.
- RSK-10 Cross-region replication lag exceeds the stated recovery point before a regional failure.
- RSK-11 Backups complete but restores fail due to undetected corruption or missing keys.
- RSK-13 Alert noise causes on-call responders to miss a genuine customer-impacting failure.
Identity Team
- RSK-05 Identity provider outage prevents workforce access to all federated applications.
- RSK-06 Conditional access policy misconfiguration locks out a business unit during rollout.
- RSK-07 Contractor entitlements persist after project completion because sponsor records are not updated.
Platform Engineering
- RSK-03 Cloud spend exceeds forecast after multi-zone redundancy and log retention are enabled.
- RSK-09 Zone failure exceeds remaining capacity and the surviving zone degrades under load.
- RSK-14 Workload token issuance failure blocks service-to-service authentication across the platform.
Security Engineering
- RSK-02 Over-permissive security-group rules copied from the legacy flat network allow lateral movement.
- RSK-04 Legacy credentials remain in configuration files after migration and are never rotated.
- RSK-08 Break-glass account credentials are used without detection or post-use review.