Cloud 101CircleEventsBlog
Download Presentations from the CSA AI Summit at RSAC Now

Download Publication

Microservices Architecture Pattern
Microservices Architecture Pattern
Who it's for:
  • Application developers and architects
  • System and security administrators
  • Security program managers
  • Information system security officers

Microservices Architecture Pattern

Release Date: 08/31/2021

This document provides a repeatable approach to architecting, developing, and deploying microservices as Microservices Architecture Patterns (MAPs). The proposed MAP contains all the information necessary for a microservice to operate independently and communicate with other microservices which, in aggregate, become the components of an application.

This vendor-neutral reference architecture decomposes into software architecture patterns represented in software and platform (enterprise) planes, and then can be built back up with the addition of security control overlays. This can be demonstrated by the successful decomposition and recomposition of microservice architecture patterns where the integral action is the overlay of security controls. 

Key Takeaways:
  • The difference between architectures and solutions
  • What Microservices Architecture Patterns (MAPs) are
  • The components of several MAPs: offload, route, aggregation, cache, proxy, authN, authZ, facade, strangler fig, circuit breaker, and adapter patterns
  • What security control overlays are
  • The components of several overlays: service, IAM, network, monitoring, cryptologic, and microservice availability and resiliency overlays
 

This publication is part of a larger series, you can find all the papers in the series here.  

Download this Resource

Prefer to access this resource without an account? Download it now.

Bookmark
Share
Related resources
Cloud Controls Matrix and CAIQ v4
Cloud Controls Matrix and CAIQ v4
HSM-as-a-Service Use Cases, Considerations, and Best Practices
HSM-as-a-Service Use Cases, Considerations, and...
Defining the Zero Trust Protect Surface
Defining the Zero Trust Protect Surface
How Continuous Controls Monitoring Brings IT Unity & Agility
How Continuous Controls Monitoring Brings IT Unity & Agility
Published: 05/10/2024
CSA Community Spotlight: Educating the Security Industry with CISO Rick Doten
CSA Community Spotlight: Educating the Security Industry with CISO ...
Published: 05/08/2024
Navigating Legacy Infrastructure: A CISO’s Strategy for Success
Navigating Legacy Infrastructure: A CISO’s Strategy for Success
Published: 05/08/2024
Is Managed Kubernetes the Right Choice for My Organization?
Is Managed Kubernetes the Right Choice for My Organization?
Published: 05/07/2024

Acknowledgements

Craig Ellrod
Craig Ellrod
Cloud Security Solutions Architect

Craig Ellrod

Cloud Security Solutions Architect

I hack therefore I am

Read more

Michael Roza
Michael Roza
Head of Risk, Audit, Control and Compliance

Michael Roza

Head of Risk, Audit, Control and Compliance

Since 2012 Michael has contributed to over 100 CSA projects completed by CSA's Internet of Things, Zero Trust/Software-Defined Perimeter, Top Threats, Cloud Control Matrix, Containers/Microservices, DevSecOps, and other working groups. He has also served as co-chair of CSA's Enterprise Architecture, Top Threats, and Security-as-a-Service working groups while also serving as the Standards Liaison Officer for IoT, ICS, EA, SECaaS, and Cloud K...

Read more

Anil Karmel
Anil Karmel
CEO, C2 Labs

Anil Karmel

CEO, C2 Labs

Anil Karmel is the Co-Founder and CEO of RegScale, which helps organizations start and stay compliant via the world's first real-time GRC platform. Formerly, Anil served as the National Nuclear Security Administration's (NNSA) Deputy Chief Technology Officer. Karmel began his government career as a Technical Staff Member of Los Alamos National Laboratory (LANL) and was responsible for inventing their cloud and collaboration technologies Kar...

Read more

Andrew Wild
Andrew Wild

Andrew Wild

Vani Murthy
Vani Murthy
Sr. Information Security Compliance Advisor, Akamai Technologies

Vani Murthy

Sr. Information Security Compliance Advisor, Akamai Technologies

Vani has 20+ years of IT experience in the areas such as Security, Risk, Compliance, Cloud services (IaaS/PaaS/SaaS) architecture

Read more

Gustavo Arreaza Headshot Missing
Gustavo Arreaza

Gustavo Arreaza

Kevin Keane Headshot Missing
Kevin Keane

Kevin Keane

Alex Rebo Headshot Missing
Alex Rebo

Alex Rebo

Namrata Kulkarni
Namrata Kulkarni
Cyber Security Architect

Namrata Kulkarni

Cyber Security Architect

John Jiang Headshot Missing
John Jiang

John Jiang

Mark Yanalitis Headshot Missing
Mark Yanalitis

Mark Yanalitis

Ankit Sharma
Ankit Sharma
Engineering Technical Leader at Cisco Systems India Pvt Ltd

Ankit Sharma

Engineering Technical Leader at Cisco Systems India Pvt Ltd

Marina Bregkou
Marina Bregkou
Senior Research Analyst, CSA EMEA

Marina Bregkou

Senior Research Analyst, CSA EMEA

Ankur Gargi Headshot Missing
Ankur Gargi

Ankur Gargi

Sean Estrada
Sean Estrada
Head of Industry Standards Engagement for AWS

Sean Estrada

Head of Industry Standards Engagement for AWS

Sean Estrada is Head of Industry Standards Engagement for AWS, where he is responsible for driving engagement with industry standards organizations and alliances. Building on over 15 years of experience in information security, audit and compliance, Sean is Amazon's internal subject matter expert on security standards design, strategy and implementation, and is Amazon's representative to the PCI Board of Advisors and the Vice President of t...

Read more

Pradeep Nambiar Headshot Missing
Pradeep Nambiar

Pradeep Nambiar

Vinod Babu Vanjarapu Headshot Missing
Vinod Babu Vanjarapu

Vinod Babu Vanjarapu

Hillary Baron
Hillary Baron
Senior Technical Director - Research, CSA

Hillary Baron

Senior Technical Director - Research, CSA

Michael Holden Headshot Missing
Michael Holden

Michael Holden

Are you a research volunteer? Request to have your profile displayed on the website here.

Interested in helping develop research with CSA?

Related Certificates & Training