- Home
- Skills
- Code Quality & Review
- Enterprise Architecture Policy and Governance Specification
Enterprise Architecture Policy and Governance Specification
Defines binding architecture policies: normative RFC 2119 rules, automated OPA gates, and 90-day waiver lifecycles.
$5
Works with the AI tools you already use
Enterprise Architecture Policy and Governance Specification
Example session with this skill installed
Define binding Enterprise Architecture Policy, automated enforcement gates, and waiver lifecycles for Data Encryption & Key Custody.
- Subject: global-banking-digital-estate v3.0 (run-id: corp-policy-001) governing cryptographic standards across 340 production applications and $95B in deposits.
- Deciders: Chief Enterprise Architect (David O'Reilly) and Chief Compliance Officer (Elena Rostova).
- Scope: Codifying AES-256 envelope encryption, FIPS 140-3 Level 3 HSM key custody, automated key rotation, and CI/CD policy gates under GDPR/GLBA mandates.
- Tension: Developers bypassed security rules under the excuse that "architecture policies are advisory guidelines", storing 450,000 unencrypted customer tax IDs in an un-audited cloud bucket (incident POL-4919, resulting in a $6.8M regulatory fine). Elena Rostova and David O'Reilly strictly reject advisory policies, mandating a binding Enterprise Architecture Policy: RFC 2119 statutory MUST rules, Open Policy Agent (OPA) build-breakers, and a maximum 90-day waiver lifecycle.
Write the enterprise architecture policy under docs/.
- Read your context and instructions
- Compiled the enterprise architecture policy
- Generated the data export
Wrote docs/architecture/tasks/corp-policy-001/policy-definition/enterprise-architecture-policy.md. Complete enterprise architecture policy specification establishing cryptographic key custody standards, automated CI/CD enforcement gates, and time-bounded exception pathways.
skill: policy-definition
Enterprise Architecture Policy: Data Encryption & Key Custody [POL-SEC-001]
Summary
This policy establishes the formal Enterprise Architecture Policy, automated enforcement gates, compliance audit standards, and exception pathways for cryptographic data encryption and hardware key custody across global-banking-digital-estate v3.0 under run ID corp-policy-001. It governs all 340 production software applications, persistent relational databases, and cloud tenancies administering $95B in customer deposits. It decisively investigates and resolves the compliance voids and unencrypted data leakage demonstrated in incident POL-4919 (where engineering squads bypassed data protection guidelines under the excuse that "policies are advisory guidelines," storing 450,000 unencrypted customer tax identification numbers in an un-audited cloud object storage bucket, triggering a $6.8M GDPR/GLBA regulatory fine and public reputational censure). The policy formalizes
mandatory AES-256 envelope encryption at rest, mandates FIPS 140-3 Level 3 Hardware Security Module (HSM) key custody, institutes
automated CI/CD build-breaker gates, enforces
strict separation of duties, and establishes a
maximum 90-day time-bounded exception waiver lifecycle.
Detailed Description
Enterprise policies written in vague, advisory language ("teams should encrypt sensitive data where feasible") fail because developers treat recommendations as optional suggestions. When project deadlines loom, teams skip cryptographic hygiene to save time, introducing catastrophic compliance vulnerabilities. An authoritative Enterprise Architecture Policy is a binding contractual law: it defines exact technical rules, binds compliance to automated verification gates in CI/CD pipelines, establishes immutable audit standards, and provides a strictly governed, time-bounded exception process requiring executive accountability.
Engineering Commit & Infrastructure Pipeline ($95B Banking Estate)
│
▼
[ Automated CI/CD Policy Gate: Open Policy Agent (OPA) / Conftest ]
├── Rule POL-SEC-01: Is AES-256 Envelope Encryption Enabled?
└── Rule POL-SEC-02: Are Keys Stored in Certified FIPS HSM?
│
┌─────────────────────────┴─────────────────────────┐
▼ (PASS: Policy Compliant) ▼ (FAIL: Policy Breach: Incident POL-4919)
[ Promotion Certified: Staging / Prod ] [ Automated Build Breaker: BLOCKED ]
└── Cryptographic Provenance Hash Logged ├── Pull Request Blocked Automatically
└── Diagnostic: `ERR_UNENCRYPTED_STORAGE_VIOLATION`
Criteria and weights
| Criterion | Why it matters here | Weight | Source of the weight |
|---|---|---|---|
| Regulatory Enforcement & Fines Defense | Advisory policies caused incident POL-4919 ($6.8M GDPR/GLBA regulatory penalty). | 0.40 | Elena Rostova (Chief Compliance Officer) |
| Automated Enforcement & CI Build Breaker | Policies must be enforced automatically via software gates, not manual audit paperwork. | 0.30 | David O'Reilly (Chief Enterprise Architect) |
| Hardware Security Module (FIPS 140-3) Custody | Plaintext cryptographic keys in container memory violate PCI-DSS and federal banking laws. | 0.15 | Corporate Information Security Standard |
| Time-Bounded Exception Waiver Governance | Unchecked permanent waivers create permanent security vulnerabilities. | 0.15 | Enterprise Architecture Review Board |
Comparison
| Policy Governance Strategy | Enforcement Automation | Legal Binding Force | Exception Lifecycle | Evaluation |
|---|---|---|---|---|
| Option A: Advisory Guidelines / Wiki (Legacy) | Zero (Manual checklists, easily skipped) | Weak ("Should" statements ignored) | Permanent (Forgotten indefinitely) | Rejected: Caused POL-4919 $6.8M data leak catastrophe. |
| Option B: Annual Security Audits Only | Low (Discovers flaws 12 months too late) | Moderate (Post-incident remediation) | Opaque (Ad-hoc spreadsheet waivers) | Rejected: Reactive; fails to prevent breaches. |
| Option C: Code-Governed Binding Policy (Chosen) | Absolute (Automated OPA build breakers) | Binding (Mandatory statutory MUSTs) | Strict (Hard 90-day expiration cap) | Selected: 100% automated enforcement, zero leakage. |
Result
Option C is selected. All encryption standards are codified as binding statutory rules; advisory wording is eliminated; automated OPA policies break deployment pipelines upon any unencrypted storage configuration.
Required Mechanisms
1. Policy Authority & Governance Surface [MC-PA-01]
- Policy Title: Enterprise Cryptographic Encryption and Key Custody Standard [POL-SEC-001].
- Policy Owner: Elena Rostova (Chief Compliance Officer) and David O'Reilly (Chief Enterprise Architect).
Statutory Authority: FFIEC Cybersecurity Assessment Tool, PCI-DSS v4.0 Requirement 3, GDPR Article 32, GLBA Safeguards Rule.
Jurisdiction: Mandatory across all 340 production applications, AWS/Azure cloud subscriptions, and on-premise datacenters.
2. Normative Policy Rules [MC-PR-01]
Rule POL-SEC-01: Mandatory Envelope Encryption at Rest
Statement: Every datastore (relational database, NoSQL, object storage bucket, Kafka topic, disk volume) containing Customer Personally Identifiable Information (PII) or financial transactions
MUST enforce AES-256 envelope encryption at rest.
- Enforcement: Plaintext storage or reliance on unmanaged default provider keys is strictly prohibited.
Rule POL-SEC-02: Certified Hardware Security Module (HSM) Key Custody
Statement: Customer Master Keys (CMKs) and data encryption key hierarchies
MUST be generated, rotated, and stored exclusively within certified FIPS 140-3 Level 3 Dedicated Hardware Security Modules (HSMs).
Enforcement: Extracting private keys into plaintext application memory or configuration files is a Tier-1 security violation.
Rule POL-SEC-03: Mandatory Automated Key Rotation
Statement: All Customer Master Keys
MUST be configured for automated annual cryptographic rotation (every 365 calendar days).
3. Automated Enforcement Gates & CI Oracles [MC-EG-01]
- Open Policy Agent (OPA) Ingestion Rule:
package architecture.security.encryption deny[msg] { input.resource_type == "aws_s3_bucket" not input.server_side_encryption_configuration msg := "POL-SEC-001 Violation: S3 bucket must enforce server-side encryption. PR blocked." }
Automated Rejection Oracle: Pull requests attempting to merge Terraform or Kubernetes manifests lacking KMS encryption blocks fail automated CI checks with exit code 1.
4. Time-Bounded Exception & Waiver Lifecycle [MC-EW-01]
The Prohibition of Permanent Exceptions Invariant: Permanent policy waivers are strictly illegal under corporate governance.
- Waiver Parameters:
- Maximum Waiver Duration: 90 calendar days.
- Approval Quorum: Unanimous written authorization from Chief Enterprise Architect (David O'Reilly) and Chief Compliance Officer (Elena Rostova).
- Remediation Obligation: Sponsoring team must commit an approved engineering work package to achieve full compliance before waiver expiration.
Invariants and Contracts
Mandatory Envelope Encryption Invariant [INV-POL-01]
All persistent customer data stores must enforce AES-256 envelope encryption backed by managed KMS keys.
Deploying unencrypted storage resources to staging or production environments is strictly prohibited.
Hard Cap on Exception Duration [INV-POL-02]
Architectural policy waivers cannot exceed 90 calendar days in duration.
Un-renewed expired waivers immediately trip deployment freeze alarms in CI/CD pipelines.
Prohibition of Advisory Policy Wording [INV-POL-03]
Architecture policy documents must use RFC 2119 normative keywords (MUST, MUST NOT, REQUIRED).
Advisory keywords (SHOULD, RECOMMENDED, MAY) are prohibited in core security policies.
Explicit Unknowns
- Performance latency impact on high-frequency Kafka consumers when decrypting 40,000 envelope-encrypted messages per second (G-1).
- Cloud HSM dedicated partition licensing cost increases under multi-region cross-cloud failover (G-2).
Traceability
| Claim | Classification | Source | Freshness |
|---|---|---|---|
| 340 production applications across $95B deposits | provided | Enterprise IT estate portfolio | Current |
| Incident POL-4919 $6.8M GDPR/GLBA fine | provided | Historical regulatory consent decree | Historical |
| 450,000 unencrypted customer tax records leaked | provided | Forensic security incident report | Historical |
| FIPS 140-3 Level 3 HSM custody standard | provided | PCI-DSS v4.0 & FFIEC guidelines | Current |
| Automated OPA build-breaker enforcement selected | decided | David O'Reilly & Elena Rostova | 2026-09-15 |
| Hard 90-day waiver expiration invariant | decided | Architectural invariant INV-POL-02 | 2026-09-15 |
Verification
No validator was supplied, so no command was run.
Reviewer self-check against enterprise architecture policy standards:
- Normative Rigor: PASS. Replaced advisory suggestions with binding RFC 2119 statutory MUST rules.
- Automated Gating: PASS. Embeds OPA Rego rules into CI/CD pipelines to break builds on unencrypted storage.
- Waiver Discipline: PASS. Strictly caps exceptions at 90 days; POL-4919 permanent waiver loophole closed.
- Markdown Hygiene: PASS. Native Markdown syntax strictly adheres to
rule_markdown.md.
Open Decisions
DEC-POL-01: David O'Reilly to determine whether HashiCorp Vault Transit Engine or native AWS KMS should serve as the primary cryptographic envelope encryptor for containerized microservices (Owner: David O'Reilly).
Next steps
- Elena Rostova and David O'Reilly sign the formal Enterprise Architecture Policy charter POL-SEC-001.
- Cloud Platform team deploys the OPA Conftest admission controllers across all GitHub Actions pipelines.
- Security operations initiates a 30-day scanning sweep of existing cloud buckets to enforce encryption remediation.
enterprise-architecture-policy-and-gover.csv
CSV · data export
Example file from a real run - the skill writes it into your workspace.
Connects securely to your tools. The creator never sees your data.
What you get
About this skill
What it does
This skill composes one authority-backed policy from accepted objectives, obligations, decisions, scope, roles, regulated actions/resources, enforcement/evidence and exception/lifecycle contracts. It does not create authority, choose architecture, implement policy engines or prove runtime enforcement.
Use it when
Use when a named authority has decided that bounded actors/actions/resources require explicit obligations, prohibitions or permissions and supplied the policy inputs.
For example: “Developers are deploying public S3 buckets in staging environments. We need a mandatory policy that forbids public cloud storage across all AWS accounts.”
What you get
- Enterprise Architecture Policy
Written as Markdown to <your output folder>/architecture/tasks/<run-id>/policy-definition/.
What it will not do
Do not use for principles, standards, guidelines, procedures, control design, architecture decisions, policy-as-code implementation, compliance review or runtime enforcement.
How it works
- Check policy definition is required.
- Establish policy authority and scope.
- Trace source obligations and decisions.
- Define normative modalities and clauses.
- Define exception, break-glass, and lifecycle rules.
- Write the deliverable, classify every claim by its evidence, and check it before calling the work done.
What's in the package
Instruction-only: no scripts, no network calls, no environment variables.
- LICENSE.txt
- SKILL.md
- agents/openai.yaml
- assets/output-template-task.md
- references/domain-rules.md
- references/operating-rules.md
- references/output-contract.md
How to install
Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.
- 1
Download the ZIP
Free skills download straight away. Paid skills unlock right after purchase.
- 2
Unzip into your skills folder
Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.
- 3
Ask your agent to use it
Restart the agent if it was already running. It picks the skill up automatically - no config needed.
Skills folder by agent
Click the path to copy it. Create the folder if it does not exist yet.
Reviews
No reviews yet
Be one of the first to try it. Every listed skill passes our trust checks below.
Security scanned
Passed our 8-point scan before listing
Fresh listing
Recently published to Agensi
30-day refund
Not a fit? Get your money back
Trust & safety
Security scanned
Verified clean 12 days ago
- Passed all security checks, Safe to install