Properties, not labels
A security property states what the system must preserve. Confidentiality limits disclosure. Integrity limits unauthorized change or destruction. Availability keeps required service accessible in its stated conditions. Authenticity supports confidence that an entity, message, or origin is what it claims to be. Accountability links relevant actions to evidence. Privacy governs appropriate processing of information about people.
These properties overlap but do not imply each other. Encryption can protect confidentiality while an attacker deletes the ciphertext. A signed event can support integrity and origin checks without proving that its actor had permission.
Scope the property
Name the asset, operation, actor, time, and condition. "Policy changes are attributable to an authenticated administrator and retained for one year" is more useful than "the logs provide accountability." Availability also needs a service level and failure model. Privacy needs a processing purpose and data boundary.
Conflicts and tradeoffs
One control can improve a property and weaken another. Detailed logs can support accountability but expose private or confidential data. A dependency that improves authorization context can reduce availability. Emergency access can aid recovery but increase authority. Record the tradeoff instead of compressing it into one security score.
Failure and residual risk
A property can hold at one layer and fail at another. Transport encryption does not protect data after a compromised endpoint reads it. Authentication does not prove that an action was authorized. Audit records do not show actions on an unmonitored path.
Pomerium boundary
Pomerium can protect route access, transport connections, identity assertions, and decision evidence within its documented boundary. The upstream application and surrounding system still determine data confidentiality, object integrity, business availability, action accountability, and privacy after the request crosses that boundary.
Evaluation checklist
- Does each requirement name a specific property and asset?
- Are authenticity, authentication, and authorization kept separate?
- Does the availability claim include a failure condition and target?
- Does evidence cover the final action rather than only the gateway decision?
- Have privacy and confidentiality effects of logs and identity data been reviewed?
