Explicit Identity
Intended security and architecture principle; specific controls must be documented separately.
BLUETRIX Trust
Architecture principles define what should be assessed and documented without claiming controls that have not been evidenced.
Security principles
Intended security and architecture principle; specific controls must be documented separately.
Intended security and architecture principle; specific controls must be documented separately.
Intended security and architecture principle; specific controls must be documented separately.
Intended security and architecture principle; specific controls must be documented separately.
Intended security and architecture principle; specific controls must be documented separately.
Intended security and architecture principle; specific controls must be documented separately.
Identity and access
A successful login alone does not automatically authorise every action.
Organisational boundaries
Principles to be assessed or intended; not a promise of complete tenant isolation.
Technical protection areas
Mechanisms without evidence are not presented as implemented.
Secure interfaces & development
Audit
Interaction Timeline, technical logging and security audit are separate information areas.
Incident Readiness
Security status
Implemented controls, improvements, measures, assessments, evidence, limitations and updates must be documented using real status data. This page does not invent status values.
Request currently available information about architecture, controls and responsibilities.