Index
Concepts
One architecture or control per entry: what it is, one diagram of a single request moving through it, what it protects, and — stated as plainly — what it does not solve.
Vendor-neutral security architecture
Not a posture, not a product category. Something asks for something, signals arrive, a policy is evaluated, a control is applied, and a verdict is recorded. Every entry here follows one request through one architecture and names what the architecture does not decide.
The 7 decisions in A remote worker opens payroll from untrusted Wi-Fi, in the order the request meets them.
Three ways in
A situation, a term, or a choice between two things that sound alike. All three land on the same diagrams.
Index
One architecture or control per entry: what it is, one diagram of a single request moving through it, what it protects, and — stated as plainly — what it does not solve.
Index
Two approaches in one shared scene with the difference marked, for when the question is not what a thing is but which one applies.
Index
A concrete situation followed decision by decision, for when you have the problem in front of you but not yet the vocabulary for it.
No acronym required
Both lists are built from the entries themselves, so nothing here points at a page with nothing behind it.
Similar names, different jobs
One shared scene per comparison, with the delta marked and a plain statement of when each choice applies.
Comparison
A VPN grants reachability to a network and then trusts you. ZTNA brokers one application per request and never puts you on the network at all.
Comparison
SSE is the security half of SASE. Where the boundary falls decides whether branch and wide-area connectivity is part of the purchase or still your problem.
Comparison
A SIEM centralises events from everything and keeps them. XDR goes deeper into one vendor's telemetry and can act on it. Most estates end up running both.