Security engineering makes a control work. Security architecture decides which controls should exist, how they fit together, and what the organisation is accepting instead. The distinction is not seniority; it is the unit of work.
Architecture is a set of constrained decisions
An architecture is the collection of decisions that are expensive to reverse: where trust boundaries sit, what the identity model is, how data is segmented, what the failure behaviour is. Everything cheap to change is implementation, and confusing the two wastes senior time on settings.
The deliverable is reasoning, not a diagram
A diagram shows a conclusion. An architecture deliverable shows the requirement, the options, the decision, the trade accepted and the residual risk. Without that chain the design cannot be reviewed, defended, or safely changed by anyone who comes later.
You are accountable for what you did not do
Every control you chose not to build is a risk someone is carrying, usually without knowing it. Making those omissions explicit and owned is the part of the job that distinguishes an architect from a designer.
Action step
Take a design you own and list the five decisions that would be expensive to reverse. That list is your actual architecture.
Tech Skills Library is independent and is not affiliated with, accredited by, or endorsed by NIST, ISO, the Cloud Security Alliance, any cloud provider, security vendor or certification body named in this course. Frameworks, control catalogues and regulatory requirements are maintained by their issuing bodies and change; always confirm current versions at the source. This course teaches architecture practice and does not issue a certification or credential.