security-architecture
Compare original and translation side by side
🇺🇸
Original
English🇨🇳
Translation
ChineseSecurity Architecture (Zero Trust & MCRA)
安全架构(Zero Trust & MCRA)
Security architecture defines how identity, endpoints, data, apps, infrastructure, and network
controls combine to protect an organisation - anchored to Zero Trust and the Microsoft
Cybersecurity Reference Architectures (MCRA), with delivery scaffolding from the Cloud
Adoption Framework Secure methodology and workload-level rigour from the Well-Architected
Framework Security pillar.
安全架构定义了身份、终端、数据、应用、基础设施和网络控制如何结合以保护组织——以Zero Trust和Microsoft Cybersecurity Reference Architectures (MCRA)为核心,以Cloud Adoption Framework Secure方法论作为交付框架,并依托Well-Architected Framework安全支柱保障工作负载层面的严谨性。
When to use
适用场景
Designing an end-to-end security target state, aligning a multi-year roadmap to a recognised
framework, or reviewing an architecture for gaps before a major programme of work.
Do not use this skill for:
- Tactical product configuration (use the product-specific skill, e.g. ,
defender-xdr)sentinel - SOC tooling architecture only (use )
unified-secops-platform - Single-workload code review (use )
threat-modelling
设计端到端安全目标状态、将多年路线图与公认框架对齐,或在重大项目开展前审查架构以发现漏洞。
请勿将此技能用于:
- 战术产品配置(请使用特定产品技能,例如、
defender-xdr)sentinel - 仅SOC工具架构设计(请使用)
unified-secops-platform - 单一工作负载代码审查(请使用)
threat-modelling
Pick the right framework for the conversation
为对话选择合适的框架
| Question being asked | Use this framework | Output |
|---|---|---|
| What is our 3-year security target state? | MCRA + CAF Secure | Capability map + roadmap |
| What capabilities cover identity / endpoints / data / apps / infra / network? | Zero Trust six pillars | Pillar maturity heatmap |
| How do we deliver the programme (strategy → operate)? | CAF Secure methodology | Workstream plan |
| Is this single workload designed securely? | Well-Architected Security pillar | Workload review |
| What threats apply to a specific design? | STRIDE / SDL (use | Threat model |
| Are we meeting a regulatory baseline? | Microsoft Cloud Security Benchmark | Compliance evidence |
Rule of thumb: Zero Trust is the principles layer. MCRA is the capability layer. CAF Secure is the delivery layer. Well-Architected is the workload layer. A real architecture uses all four - do not try to substitute one for another.
| 问题类型 | 使用框架 | 输出结果 |
|---|---|---|
| 我们的3年安全目标状态是什么? | MCRA + CAF Secure | 能力图谱 + 路线图 |
| 哪些能力覆盖身份/终端/数据/应用/基础设施/网络? | Zero Trust六大支柱 | 支柱成熟度热力图 |
| 我们如何交付项目(从战略到运营)? | CAF Secure方法论 | 工作流计划 |
| 这个单一工作负载的设计是否安全? | Well-Architected安全支柱 | 工作负载审查报告 |
| 特定设计面临哪些威胁? | STRIDE / SDL(请使用 | 威胁模型 |
| 我们是否符合监管基线? | Microsoft Cloud Security Benchmark | 合规证据 |
经验法则: Zero Trust是原则层。MCRA是能力层。CAF Secure是交付层。Well-Architected是工作负载层。实际架构需同时使用这四个框架——不要尝试用其中一个替代其他框架。
Approach
实施方法
- Anchor on Zero Trust principles first - Verify explicitly, use least-privilege access, assume breach. Every later decision must trace back to one of these. Verify: every control in your design can be tagged to one of the three principles. If it cannot, ask why it exists.
- Map the six Zero Trust pillars - identity, endpoints, data, apps, infrastructure, network, with visibility/analytics and automation across all. Score current maturity per pillar (Traditional / Advanced / Optimal) so investment lands where the gap is widest. Verify: pillar heatmap shows clear deltas; you can name the top two pillars to invest in.
- Validate identity is the primary control plane - if identity is weak, no other pillar compensates. Confirm MFA coverage, privileged access design (PIM, PAW), and Conditional Access posture before investing heavily in network, data, or endpoint pillars. Verify: % of human accounts behind phishing-resistant MFA and % of privileged accounts in PIM are baselined and on a roadmap.
- Anchor capabilities to MCRA - Use the Microsoft Cybersecurity Reference Architectures to map Microsoft products (Defender, Sentinel, Entra, Purview, Intune, Defender for Cloud) to the functions they cover and to validate no capability is missing or duplicated. Verify: MCRA poster overlaid with your current/planned products shows zero unaddressed functions in your scope.
- Build defense in depth - layer preventive, detective, and responsive controls so no single control failure equals a breach. For each asset class, name at least one preventive and one detective control. Verify: removing any one control still leaves a detection or compensating control in place.
- Sequence the roadmap by risk and dependency - Current state → target state per pillar, ordered so prerequisites land first (e.g. identity hygiene before data classification, log ingestion before XDR, posture management before automation). Verify: roadmap shows ordered milestones with named owners and risks; not a flat backlog.
- Build monitoring and response in, not on - the SIEM/XDR architecture is part of the design, not a follow-up project. Confirm log sources, retention, and response handoffs. Verify: every pillar produces signals into a documented detection pipeline.
- 首先以Zero Trust原则为核心——显式验证、使用最小权限访问、假设已遭入侵。后续所有决策都必须追溯到这三个原则之一。 验证:设计中的每一项控制都能关联到这三个原则中的一个。如果不能,需说明其存在的理由。
- 映射Zero Trust六大支柱——身份、终端、数据、应用、基础设施、网络,并覆盖所有支柱的可见性/分析和自动化能力。为每个支柱的当前成熟度打分(传统/进阶/最优),以便将投资投向差距最大的领域。 验证:支柱热力图显示明确的差距;你能指出最需要投资的前两大支柱。
- 验证身份是主要控制平面——如果身份机制薄弱,其他支柱无法弥补。在大力投资网络、数据或终端支柱之前,确认MFA覆盖率、特权访问设计(PIM、PAW)以及条件访问态势。 验证:已建立抗钓鱼MFA覆盖的人工账户比例和纳入PIM的特权账户比例基线,并制定了路线图。
- 以MCRA为核心映射能力——使用Microsoft Cybersecurity Reference Architectures将微软产品(Defender、Sentinel、Entra、Purview、Intune、Defender for Cloud)映射到其覆盖的功能,验证无能力缺失或重复。 验证:叠加当前/计划产品的MCRA海报显示,你的范围内没有未覆盖的功能。
- 构建纵深防御——分层部署预防性、检测性和响应性控制,确保单一控制失效不会导致 breach。针对每个资产类别,至少指定一项预防性控制和一项检测性控制。 验证:移除任何一项控制后,仍有检测或补偿控制生效。
- 按风险和依赖关系规划路线图顺序——按支柱划分当前状态→目标状态,按先决条件优先的顺序排列(例如,身份治理优先于数据分类,日志采集优先于XDR,态势管理优先于自动化)。 验证:路线图显示有序的里程碑,包含指定负责人和风险;而非扁平化的待办事项列表。
- 内置监控与响应能力,而非事后添加——SIEM/XDR架构是设计的一部分,而非后续项目。确认日志源、保留期限和响应交接流程。 验证:每个支柱都能向已记录的检测管道生成信号。
Guardrails
约束规则
- Architecture must be driven by business risk and data sensitivity - not product inventory, vendor pressure, or "what we already own". Start from the threat and the asset, then pick the control.
- Identity is non-negotiable. No Zero Trust architecture works if MFA, privileged access, and Conditional Access are weak. Fix this pillar first.
- Visibility and automation are cross-cutting - they are not a seventh pillar but a prerequisite for all six. Design log ingestion and orchestration up front.
- Defense in depth, not defence in expense - layered controls only count if each layer detects/blocks a different class of failure. Two SIEMs are not defence in depth.
- A roadmap without owners is a wish list. Every milestone needs a named owner and a measurable exit criterion.
- Re-baseline annually. MCRA, CAF Secure, and the Zero Trust pillars all evolve - last year's reference architecture is not this year's.
- 架构必须由业务风险和数据敏感度驱动——而非产品清单、供应商压力或“我们已拥有的资源”。从威胁和资产入手,再选择控制措施。
- 身份机制是不可协商的。 如果MFA、特权访问和条件访问薄弱,Zero Trust架构无法生效。优先修复此支柱。
- 可见性和自动化是跨领域要求——它们不是第七个支柱,而是所有六大支柱的先决条件。提前设计日志采集和编排能力。
- 纵深防御,而非过度投入——分层控制仅在每层检测/阻止不同类型失效时才有效。部署两个SIEM不属于纵深防御。
- 没有负责人的路线图只是愿望清单。 每个里程碑都需要指定负责人和可衡量的退出标准。
- 每年重新基线化。 MCRA、CAF Secure和Zero Trust支柱都在演进——去年的参考架构不适用于今年。
Common anti-patterns
常见反模式
- "We bought Defender / Sentinel so we are Zero Trust." Products do not equal architecture. Without the principles, pillars, and operating model, you have shelfware.
- Investing in network or data pillars while identity remains weak. Adversaries pivot through the weakest pillar; identity is almost always it.
- Treating the SIEM as an afterthought. Detection retrofitted to an existing design has blind spots that are expensive to close later.
- A 60-page architecture document with no roadmap. Architecture without sequencing is not actionable. Pair every target state with the next 90 days of work.
- Using Well-Architected as the org-wide framework. WAF is workload-level; use CAF Secure for the programme view.
- “我们购买了Defender / Sentinel,所以已经实现了Zero Trust。” 产品不等于架构。没有原则、支柱和运营模式,这些只是闲置资源。
- 在身份机制仍薄弱时投资网络或数据支柱。 攻击者会通过最薄弱的支柱渗透;身份几乎总是最薄弱的环节。
- 将SIEM视为事后补充。 为现有设计 retrofit检测能力会留下难以弥补的盲区。
- 一份60页的架构文档却没有路线图。 没有执行顺序的架构无法落地。每个目标状态都要搭配未来90天的具体工作。
- 将Well-Architected用作全组织框架。 WAF是工作负载层面的框架;请使用CAF Secure进行项目层面规划。
Example prompts
示例提示词
Design a Zero Trust security architecture aligned to MCRA.Apply the Cloud Adoption Framework secure methodology to our 3-year roadmap.How do I build defence in depth across identity, network, and data?Review my workload design against the Well-Architected security pillar.Score our current state across the six Zero Trust pillars.
Design a Zero Trust security architecture aligned to MCRA.Apply the Cloud Adoption Framework secure methodology to our 3-year roadmap.How do I build defence in depth across identity, network, and data?Review my workload design against the Well-Architected security pillar.Score our current state across the six Zero Trust pillars.
Microsoft Learn
Microsoft Learn资源
- Zero Trust overview: https://learn.microsoft.com/security/zero-trust/zero-trust-overview
- MCRA (Microsoft Cybersecurity Reference Architectures): https://learn.microsoft.com/security/adoption/mcra
- CAF Secure methodology: https://learn.microsoft.com/azure/cloud-adoption-framework/secure/
- Well-Architected Security pillar: https://learn.microsoft.com/azure/well-architected/security/
- Microsoft Cloud Security Benchmark: https://learn.microsoft.com/security/benchmark/azure/
- Zero Trust deployment guides: https://learn.microsoft.com/security/zero-trust/deploy/overview
- Zero Trust概述:https://learn.microsoft.com/security/zero-trust/zero-trust-overview
- MCRA(Microsoft Cybersecurity Reference Architectures):https://learn.microsoft.com/security/adoption/mcra
- CAF Secure方法论:https://learn.microsoft.com/azure/cloud-adoption-framework/secure/
- Well-Architected安全支柱:https://learn.microsoft.com/azure/well-architected/security/
- Microsoft Cloud Security Benchmark:https://learn.microsoft.com/security/benchmark/azure/
- Zero Trust部署指南:https://learn.microsoft.com/security/zero-trust/deploy/overview