Guidance
Domain Name Guidance
A practical guide to domain names, ownership, renewal management, and the risks created by poor domain administration.
Read guidanceFrameworks, guidance, and publications for practical security architecture
Assured Control
Assured Control is a portfolio of practical architecture work: published thinking, reusable models, downloadable diagrams, and advice shaped by real delivery and operating experience.
Content
Real working artefacts rather than placeholder marketing copy
Focus
Advice, models, and publications that can be reused in practice
Use
Reference material for architects, programme teams, and operators
What’s inside
01
Downloadable matrices, ontologies, posters, and supporting diagrams
02
Practical guidance on domains, certificates, security operations, and policy
03
Published articles, long-form papers, and book contributions
20+
downloadable frameworks and diagrams
16
core pages and specialist topics
2005
origin of the Controls Matrix work
What This Site Is For
The priority here is not the shell of the site. It is the body of work: the controls matrix, the risk ontology, frameworks, posters, architecture writing, and practical guidance that supports real programmes and decisions.
A resource for practical security architecture with guidance, examples, and templates designed to make security work more effective in the real world.
What You Can Find
Guidance
Guidance
A practical guide to domain names, ownership, renewal management, and the risks created by poor domain administration.
Read guidanceGuidance
Guidance for managing digital certificates across internal and external environments, with an emphasis on lifecycle discipline and operational reliability.
Read guidanceGuidance
A governance-oriented framework for certificate lifecycle controls, technical standards, compliance alignment, and continuous assurance.
Read guidanceGuidance
A strategic view of when and how to implement or transition to a new SOC or MDR provider.
Read guidanceFeatured Resources
matrix
ResourceThe long-running Assured Control matrix that organizes security domains, controls, and business drivers into a usable working taxonomy.
5 downloads
Explore resource
ontology
ResourceA structured way to define threats, vulnerabilities, controls, metrics, and their relationships in a business-led risk model.
5 downloads
Explore resourcedownload bundle
ResourceA curated library of ontologies, frameworks, presentations, and supporting diagram bundles from the original Models and Other Madness section.
12 downloads
Explore resourcePopular Downloads
Download
Security Controls Matrix
Large-format PDF of the Assured Control matrix.
Download
Risk Ontology
Scalable PDF version of the risk ontology.
Download
Cloud Architecture Posters
Supporting diagram bundle for the business-driven cloud architecture material.
Publications
Assured Control
A long-form paper on how security architecture has evolved across enterprise strategy, solution delivery, and live operations.
Assured Control
A long-form paper on how security architecture has evolved across enterprise strategy, solution delivery, and live operations.
Medium
A curated publication entry for the business-driven cloud architecture writing and its related presentation material.
Medium
A curated publication entry for the business-driven cloud architecture writing and its related presentation material.
Taylor & Francis
A publication entry covering the book contribution on the role of enterprise security architecture in the GRC landscape.
Taylor & Francis
A publication entry covering the book contribution on the role of enterprise security architecture in the GRC landscape.