LOGBOOK

HELP

Quiz Entry - updated: 2026.09.18

Why is there no single authoritative definition of "cyber security architecture", and what should you do about that in practice?

Neither half of the term is standardised — "cyber security" and "architecture" are both practitioner words shaped by usage, not by one international standard — so you work from common usage and, in a real conversation, pin down what the other side means.

There is no ISO or IEEE clause that fixes the term the way, say, ISO/IEC 27001 fixes what an ISMS is. Both components are loose:

  • "Cyber security" is used in a narrow sense as a straight synonym for IT security, and in a wider sense — the one that makes the discipline interesting — as the security of all cyber systems, industrial control and embedded devices included.
  • "Architecture" is borrowed from building and reused across IT and its neighbouring disciplines (enterprise architecture, solution architecture, software architecture, security architecture), each with its own tradition of what an "architecture" deliverable actually is.

The practical consequences are real rather than academic:

  • Two people can agree to "improve the cyber security architecture" and mean completely different deliverables — a network diagram, a target-state paper, a set of policies, or a rebuild programme.
  • Job adverts for "security architect" describe wildly different jobs.
  • When you read a document, the author's definition governs; when you write one, define your terms early.

Tip: treat it like the word "platform". Everybody uses it, nobody means quite the same thing, and the cheap fix is one sentence of definition at the top of your document.

Go deeper:

From Quiz: CSARCH / What Cyber Security Architecture Is, and Who It Is For | Updated: Sep 18, 2026