03 — Visual Memory Map / Framework Atlas
These are text-first redraw maps so the structure stays readable in GitHub. Attempt each map from memory before opening its answer block.
Maps
- Security requirement sources
- Risk chain
- Four A’s + Entitlement
- Restriction stack
- Security activity flow
- Policy to evidence
- Role-based access
- Masking decision
- Privilege-risk discriminator
- Monitoring and audit
- Outsourcing/cloud accountability
- Governance measurement
Work in groups
- Maps 1–3 — Requirements, Risk, Identity/Access
- Maps 4–6 — Restrictions, Activity Flow, Policy/Evidence
- Maps 7–9 — Roles, Masking, Privilege Risk
- Maps 10–12 — Monitoring, Cloud Accountability, Metrics
Final visual test: rebuild Maps 3, 4, 6, 8, 9, 10, and 11 without looking, then change one fact in each example and explain why the classification changes.