Security Architecture and Lightweight Formal Reasoning
Competency Contract
- Primary competency: SE-ENGINEERING-001
- Mastery: explain, apply, develop, and evaluate as required by the semester assessment
- Status: required evidence extension; it does not add a semester or increase the advertised duration
Required Work
Add architectural threat modelling and privacy design; state invariants and state transitions; use a lightweight specification or model-based test; automate a security fitness function.
Evidence Contract
- trust-boundary diagram
- privacy ADR
- invariant/state model
- model-based test
- security fitness-function result.
Assessment Integration
- Project: produce the evidence in the semester repository rather than as detached prose.
- Checkpoint: show the evidence exists and identify its highest-risk gap.
- Cumulative review: connect the work to current, previous, and two-semesters-back knowledge.
- Exam: evaluate a new case and reject an attractive but unsafe or unsupported alternative.
- Rubric: every required evidence category must pass; strengths cannot average away a missing category.
- Answer key: calibrate the shape of evidence without prescribing one implementation.
Oral Defense
Defend one invariant violation, one rejected architecture, and how the automated check prevents regression.
AI-Use Declaration
Record tools and models used, material output accepted, rejected suggestions, and independent verification. Undeclared generated evidence fails the integrity gate.
Reading Route
Start with the linked semester concepts and labs. Use local books selectively for conceptual depth and current official standards for normative requirements. Stop reading when you can produce and defend the required evidence.