Enterprise Architecture Policy and Governance Specification

    1

    Defines binding architecture policies: normative RFC 2119 rules, automated OPA gates, and 90-day waiver lifecycles.

    $5

    Secure checkout via Stripe

    30-day refund guarantee

    Converts to your local currency at checkout

    Security scanned

    Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIMuseMuseOpenClawOpenClaw+21 more

    Enterprise Architecture Policy and Governance Specification

    Example session with this skill installed

    Define binding Enterprise Architecture Policy, automated enforcement gates, and waiver lifecycles for Data Encryption & Key Custody.

    • Subject: global-banking-digital-estate v3.0 (run-id: corp-policy-001) governing cryptographic standards across 340 production applications and $95B in deposits.
    • Deciders: Chief Enterprise Architect (David O'Reilly) and Chief Compliance Officer (Elena Rostova).
    • Scope: Codifying AES-256 envelope encryption, FIPS 140-3 Level 3 HSM key custody, automated key rotation, and CI/CD policy gates under GDPR/GLBA mandates.
    • Tension: Developers bypassed security rules under the excuse that "architecture policies are advisory guidelines", storing 450,000 unencrypted customer tax IDs in an un-audited cloud bucket (incident POL-4919, resulting in a $6.8M regulatory fine). Elena Rostova and David O'Reilly strictly reject advisory policies, mandating a binding Enterprise Architecture Policy: RFC 2119 statutory MUST rules, Open Policy Agent (OPA) build-breakers, and a maximum 90-day waiver lifecycle.

    Write the enterprise architecture policy under docs/.

    • Read your context and instructions
    • Compiled the enterprise architecture policy
    • Generated the data export

    Wrote docs/architecture/tasks/corp-policy-001/policy-definition/enterprise-architecture-policy.md. Complete enterprise architecture policy specification establishing cryptographic key custody standards, automated CI/CD enforcement gates, and time-bounded exception pathways.


    skill: policy-definition

    Enterprise Architecture Policy: Data Encryption & Key Custody [POL-SEC-001]

    Summary

    This policy establishes the formal Enterprise Architecture Policy, automated enforcement gates, compliance audit standards, and exception pathways for cryptographic data encryption and hardware key custody across global-banking-digital-estate v3.0 under run ID corp-policy-001. It governs all 340 production software applications, persistent relational databases, and cloud tenancies administering $95B in customer deposits. It decisively investigates and resolves the compliance voids and unencrypted data leakage demonstrated in incident POL-4919 (where engineering squads bypassed data protection guidelines under the excuse that "policies are advisory guidelines," storing 450,000 unencrypted customer tax identification numbers in an un-audited cloud object storage bucket, triggering a $6.8M GDPR/GLBA regulatory fine and public reputational censure). The policy formalizes

    mandatory AES-256 envelope encryption at rest, mandates FIPS 140-3 Level 3 Hardware Security Module (HSM) key custody, institutes

    automated CI/CD build-breaker gates, enforces

    strict separation of duties, and establishes a

    maximum 90-day time-bounded exception waiver lifecycle.

    Detailed Description

    Enterprise policies written in vague, advisory language ("teams should encrypt sensitive data where feasible") fail because developers treat recommendations as optional suggestions. When project deadlines loom, teams skip cryptographic hygiene to save time, introducing catastrophic compliance vulnerabilities. An authoritative Enterprise Architecture Policy is a binding contractual law: it defines exact technical rules, binds compliance to automated verification gates in CI/CD pipelines, establishes immutable audit standards, and provides a strictly governed, time-bounded exception process requiring executive accountability.

    Engineering Commit & Infrastructure Pipeline ($95B Banking Estate)
                                       │
                                       ▼
    [ Automated CI/CD Policy Gate: Open Policy Agent (OPA) / Conftest ]
      ├── Rule POL-SEC-01: Is AES-256 Envelope Encryption Enabled?
      └── Rule POL-SEC-02: Are Keys Stored in Certified FIPS HSM?
                                       │
             ┌─────────────────────────┴─────────────────────────┐
             ▼ (PASS: Policy Compliant)                          ▼ (FAIL: Policy Breach: Incident POL-4919)
    [ Promotion Certified: Staging / Prod ]             [ Automated Build Breaker: BLOCKED ]
      └── Cryptographic Provenance Hash Logged            ├── Pull Request Blocked Automatically
                                                          └── Diagnostic: `ERR_UNENCRYPTED_STORAGE_VIOLATION`
    

    Criteria and weights

    CriterionWhy it matters hereWeightSource of the weight
    Regulatory Enforcement & Fines DefenseAdvisory policies caused incident POL-4919 ($6.8M GDPR/GLBA regulatory penalty).0.40Elena Rostova (Chief Compliance Officer)
    Automated Enforcement & CI Build BreakerPolicies must be enforced automatically via software gates, not manual audit paperwork.0.30David O'Reilly (Chief Enterprise Architect)
    Hardware Security Module (FIPS 140-3) CustodyPlaintext cryptographic keys in container memory violate PCI-DSS and federal banking laws.0.15Corporate Information Security Standard
    Time-Bounded Exception Waiver GovernanceUnchecked permanent waivers create permanent security vulnerabilities.0.15Enterprise Architecture Review Board

    Comparison

    Policy Governance StrategyEnforcement AutomationLegal Binding ForceException LifecycleEvaluation
    Option A: Advisory Guidelines / Wiki (Legacy)Zero (Manual checklists, easily skipped)Weak ("Should" statements ignored)Permanent (Forgotten indefinitely)Rejected: Caused POL-4919 $6.8M data leak catastrophe.
    Option B: Annual Security Audits OnlyLow (Discovers flaws 12 months too late)Moderate (Post-incident remediation)Opaque (Ad-hoc spreadsheet waivers)Rejected: Reactive; fails to prevent breaches.
    Option C: Code-Governed Binding Policy (Chosen)Absolute (Automated OPA build breakers)Binding (Mandatory statutory MUSTs)Strict (Hard 90-day expiration cap)Selected: 100% automated enforcement, zero leakage.

    Result

    Option C is selected. All encryption standards are codified as binding statutory rules; advisory wording is eliminated; automated OPA policies break deployment pipelines upon any unencrypted storage configuration.


    Required Mechanisms

    1. Policy Authority & Governance Surface [MC-PA-01]
    • Policy Title: Enterprise Cryptographic Encryption and Key Custody Standard [POL-SEC-001].
    • Policy Owner: Elena Rostova (Chief Compliance Officer) and David O'Reilly (Chief Enterprise Architect).

    Statutory Authority: FFIEC Cybersecurity Assessment Tool, PCI-DSS v4.0 Requirement 3, GDPR Article 32, GLBA Safeguards Rule.

    Jurisdiction: Mandatory across all 340 production applications, AWS/Azure cloud subscriptions, and on-premise datacenters.

    2. Normative Policy Rules [MC-PR-01]
    Rule POL-SEC-01: Mandatory Envelope Encryption at Rest

    Statement: Every datastore (relational database, NoSQL, object storage bucket, Kafka topic, disk volume) containing Customer Personally Identifiable Information (PII) or financial transactions

    MUST enforce AES-256 envelope encryption at rest.

    • Enforcement: Plaintext storage or reliance on unmanaged default provider keys is strictly prohibited.
    Rule POL-SEC-02: Certified Hardware Security Module (HSM) Key Custody

    Statement: Customer Master Keys (CMKs) and data encryption key hierarchies

    MUST be generated, rotated, and stored exclusively within certified FIPS 140-3 Level 3 Dedicated Hardware Security Modules (HSMs).

    Enforcement: Extracting private keys into plaintext application memory or configuration files is a Tier-1 security violation.

    Rule POL-SEC-03: Mandatory Automated Key Rotation

    Statement: All Customer Master Keys

    MUST be configured for automated annual cryptographic rotation (every 365 calendar days).

    3. Automated Enforcement Gates & CI Oracles [MC-EG-01]
    • Open Policy Agent (OPA) Ingestion Rule:
      package architecture.security.encryption
      
      deny[msg] {
          input.resource_type == "aws_s3_bucket"
          not input.server_side_encryption_configuration
          msg := "POL-SEC-001 Violation: S3 bucket must enforce server-side encryption. PR blocked."
      }
      

    Automated Rejection Oracle: Pull requests attempting to merge Terraform or Kubernetes manifests lacking KMS encryption blocks fail automated CI checks with exit code 1.

    4. Time-Bounded Exception & Waiver Lifecycle [MC-EW-01]

    The Prohibition of Permanent Exceptions Invariant: Permanent policy waivers are strictly illegal under corporate governance.

    • Waiver Parameters:
      • Maximum Waiver Duration: 90 calendar days.
      • Approval Quorum: Unanimous written authorization from Chief Enterprise Architect (David O'Reilly) and Chief Compliance Officer (Elena Rostova).
      • Remediation Obligation: Sponsoring team must commit an approved engineering work package to achieve full compliance before waiver expiration.

    Invariants and Contracts

    Mandatory Envelope Encryption Invariant [INV-POL-01]
      All persistent customer data stores must enforce AES-256 envelope encryption backed by managed KMS keys.
      Deploying unencrypted storage resources to staging or production environments is strictly prohibited.
    
    Hard Cap on Exception Duration [INV-POL-02]
      Architectural policy waivers cannot exceed 90 calendar days in duration.
      Un-renewed expired waivers immediately trip deployment freeze alarms in CI/CD pipelines.
    
    Prohibition of Advisory Policy Wording [INV-POL-03]
      Architecture policy documents must use RFC 2119 normative keywords (MUST, MUST NOT, REQUIRED).
      Advisory keywords (SHOULD, RECOMMENDED, MAY) are prohibited in core security policies.
    

    Explicit Unknowns

    • Performance latency impact on high-frequency Kafka consumers when decrypting 40,000 envelope-encrypted messages per second (G-1).
    • Cloud HSM dedicated partition licensing cost increases under multi-region cross-cloud failover (G-2).

    Traceability

    ClaimClassificationSourceFreshness
    340 production applications across $95B depositsprovidedEnterprise IT estate portfolioCurrent
    Incident POL-4919 $6.8M GDPR/GLBA fineprovidedHistorical regulatory consent decreeHistorical
    450,000 unencrypted customer tax records leakedprovidedForensic security incident reportHistorical
    FIPS 140-3 Level 3 HSM custody standardprovidedPCI-DSS v4.0 & FFIEC guidelinesCurrent
    Automated OPA build-breaker enforcement selecteddecidedDavid O'Reilly & Elena Rostova2026-09-15
    Hard 90-day waiver expiration invariantdecidedArchitectural invariant INV-POL-022026-09-15

    Verification

    No validator was supplied, so no command was run.

    Reviewer self-check against enterprise architecture policy standards:

    • Normative Rigor: PASS. Replaced advisory suggestions with binding RFC 2119 statutory MUST rules.
    • Automated Gating: PASS. Embeds OPA Rego rules into CI/CD pipelines to break builds on unencrypted storage.
    • Waiver Discipline: PASS. Strictly caps exceptions at 90 days; POL-4919 permanent waiver loophole closed.
    • Markdown Hygiene: PASS. Native Markdown syntax strictly adheres to rule_markdown.md.

    Open Decisions

    • DEC-POL-01: David O'Reilly to determine whether HashiCorp Vault Transit Engine or native AWS KMS should serve as the primary cryptographic envelope encryptor for containerized microservices (Owner: David O'Reilly).

    Next steps

    1. Elena Rostova and David O'Reilly sign the formal Enterprise Architecture Policy charter POL-SEC-001.
    2. Cloud Platform team deploys the OPA Conftest admission controllers across all GitHub Actions pipelines.
    3. Security operations initiates a 30-day scanning sweep of existing cloud buckets to enforce encryption remediation.

    enterprise-architecture-policy-and-gover.csv

    CSV · data export

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    What you get

    Formalize architecture decisions into normative RFC 2119 policy clauses.Define automated enforcement gates and exception lifecycle contracts.Trace legal and regulatory obligations to specific engineering constraints.Establish clear policy authorities, scopes, and 90-day waiver rules.

    About this skill

    What it does

    This skill composes one authority-backed policy from accepted objectives, obligations, decisions, scope, roles, regulated actions/resources, enforcement/evidence and exception/lifecycle contracts. It does not create authority, choose architecture, implement policy engines or prove runtime enforcement.

    Use it when

    Use when a named authority has decided that bounded actors/actions/resources require explicit obligations, prohibitions or permissions and supplied the policy inputs.

    For example: “Developers are deploying public S3 buckets in staging environments. We need a mandatory policy that forbids public cloud storage across all AWS accounts.”

    What you get

    • Enterprise Architecture Policy

    Written as Markdown to <your output folder>/architecture/tasks/<run-id>/policy-definition/.

    What it will not do

    Do not use for principles, standards, guidelines, procedures, control design, architecture decisions, policy-as-code implementation, compliance review or runtime enforcement.

    How it works

    1. Check policy definition is required.
    2. Establish policy authority and scope.
    3. Trace source obligations and decisions.
    4. Define normative modalities and clauses.
    5. Define exception, break-glass, and lifecycle rules.
    6. Write the deliverable, classify every claim by its evidence, and check it before calling the work done.

    What's in the package

    Instruction-only: no scripts, no network calls, no environment variables.

    • LICENSE.txt
    • SKILL.md
    • agents/openai.yaml
    • assets/output-template-task.md
    • references/domain-rules.md
    • references/operating-rules.md
    • references/output-contract.md

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    Fresh listing

    Recently published to Agensi

    30-day refund

    Not a fit? Get your money back

    Trust & safety

    Security scanned

    Verified clean 12 days ago

    • Passed all security checks, Safe to install

    Listed12 days ago

    What's inside

    Frequently Asked Questions