Skip to content

7. Appendices

Recommended ISO 42010 Recommended

Define terms, acronyms, and abbreviations used in this document:

TermDefinition
ADArchitecture Description — ISO 42010 term for the work product expressing an architecture
ADSArchitecture Description Standard — this standard
ADRArchitecture Decision Record
APMApplication Performance Monitoring
ARBArchitecture Review Board — a common form of architecture governance body
AZAvailability Zone
BYODBring Your Own Device
CDCChange Data Capture
CDNContent Delivery Network
CI/CDContinuous Integration / Continuous Deployment
CISOChief Information Security Officer
CMDBConfiguration Management Database
CQRSCommand Query Responsibility Segregation
DASTDynamic Application Security Testing
DBADatabase Administrator
DMSDatabase Migration Service
DPIAData Protection Impact Assessment
DRDisaster Recovery
EDREndpoint Detection and Response
ETLExtract, Transform, Load
EUCEnd User Computing
FaaSFunction as a Service
FinOpsCloud Financial Operations — a practice for managing cloud costs
HLDHigh Level Design — the conceptual-level design content within a SAD (Sections 3–4)
HSMHardware Security Module
IaaSInfrastructure as a Service
IAMIdentity and Access Management
JDBCJava Database Connectivity
KMSKey Management Service
LIALegitimate Interests Assessment
mTLSMutual Transport Layer Security
NASNetwork Attached Storage
NFRNon-Functional Requirement
NOCNetwork Operations Centre
ODBCOpen Database Connectivity
OIDCOpenID Connect
PaaSPlatform as a Service
PCI-DSSPayment Card Industry Data Security Standard
PIAPrivacy Impact Assessment
PIIPersonally Identifiable Information
QoSQuality of Service
RAIDRisks, Assumptions, Issues, Dependencies — a project governance log
RDPRemote Desktop Protocol
RESTRepresentational State Transfer — an architectural style for APIs
RPORecovery Point Objective — maximum acceptable data loss measured in time
RTORecovery Time Objective — maximum acceptable downtime after an incident
SaaSSoftware as a Service
SADSolution Architecture Document (originally “Software Architecture Document” in RUP)
SAMLSecurity Assertion Markup Language
SANStorage Area Network
SASTStatic Application Security Testing
SCASoftware Composition Analysis
SDLCSoftware Development Lifecycle
SFTPSSH File Transfer Protocol
SIEMSecurity Information and Event Management
SLAService Level Agreement
SPISensitive Personal Information
SRESite Reliability Engineering
SSOSingle Sign-On
TCOTotal Cost of Ownership
TOGAFThe Open Group Architecture Framework
VDIVirtual Desktop Infrastructure
VPNVirtual Private Network
WAF (firewall)Web Application Firewall — a network security control
WAF (framework)Well-Architected Framework — cloud provider architecture guidance (AWS, Azure, GCP, Oracle, IBM)
[additional terms][definitions]

Guidance

A glossary ensures shared understanding across all readers. Include:

  • All acronyms used in the document (even common ones — not everyone knows what RTO means)
  • Organisation-specific terminology
  • Technical terms that may be unfamiliar to non-technical stakeholders
  • Define terms on first use in the document, and collect them all here for reference
Recommended

List documents referenced by or related to this SAD:

DocumentVersionDescriptionLocation
[document name][version][what it covers][link or reference]
Recommended

List the standards, design patterns, and principles referenced throughout this document:

Standard / Pattern IDNameVersionApplicability
[ID][name][version][which sections reference it]