Phase 3: Enterprise Architecture + Security (Weeks 13β16)
Objective: Raise the Phase 2 artifacts to the enterprise level: defensible architecture design (leading toward AZ-305) and AI security (leading toward SC-500) with threat modeling, guardrails, and a reusable enterprise checklist.
π― Expected Outcomesβ
By completing this phase:
- Threat model for the RAG/agent system with prioritized mitigations
- Solid progress in AZ-305 with one documented architecture decision (ADR)
- Red-team / guardrails exercise against your own AI system
- Reusable enterprise security and architecture checklist
- Ready for Gate CP3 (Week 16)
The anchor certifications are AZ-305 (architecture) and SC-500 (cloud & AI security). Open frameworks (OWASP LLM, MITRE ATLAS, NIST AI RMF) are used as a common risk language.
Week 13 β Threat model + mitigationsβ
Objective: model threats specific to AI systems (not only the traditional app).
| Resource | Language | Type |
|---|---|---|
| OWASP Top 10 for LLM Applications | π¬π§ | Framework |
| MITRE ATLAS | π¬π§ | Threat matrix |
| Microsoft: Threat Modeling AI/ML | πͺπΈ | Guide |
Deliverable: threat model document for the Phase 2 system β prompt injection, data leakage, poisoning, model DoS β with mitigations prioritized by risk.
Week 14 β AZ-305: progress + security decisionβ
Objective: advance the architecture certification and ground one design decision.
| Resource | Language | Type |
|---|---|---|
| AZ-305 Study Guide | πͺπΈ | Official guide |
| Azure Well-Architected Framework | πͺπΈ | Framework |
| Architecture Decision Records (ADR) | πͺπΈ | Practice |
Deliverable: ADR documenting a key architecture decision (identity, network, sensitive data storage, or model hosting) with alternatives and trade-offs.
Week 15 β Red-team / guardrails + enterprise checklistβ
Objective: attack your own system and add defenses.
| Resource | Language | Type |
|---|---|---|
| SC-500 Study Guide | πͺπΈ | Official guide |
| Azure AI Content Safety | πͺπΈ | Service |
| PyRIT β Python Risk Identification Toolkit | π¬π§ | Open tool |
Deliverable: red-team report (adversarial prompts + results) + implemented guardrails (content filter, output validation) + enterprise checklist for AI security.
Week 16 β CP3 close: architecture + securityβ
Objective: consolidate architecture and security into a presentable package.
| Resource | Language | Type |
|---|---|---|
| NIST AI Risk Management Framework | π¬π§ | Framework |
| ISO/IEC 42001 | π¬π§ | Standard |
Checklist for Gate CP3:
- Threat model with prioritized mitigations
- Architecture ADR published
- Red-team + guardrails demonstrated
- Reusable enterprise security checklist
- Verifiable progress in AZ-305 and SC-500
π Phase 3 Checklistβ
- Threat model for the RAG/agent system (OWASP LLM + MITRE ATLAS)
- ADR with architecture decision and trade-offs
- Red-team exercise with applied guardrails
- Enterprise security and architecture checklist
- Exam plan for AZ-305 and SC-500
- Gate CP3 approved
v4 Operationsβ
π Resume Valueβ
"I designed and secured an enterprise-level AI system: threat model mapped to OWASP LLM Top 10 and MITRE ATLAS, architecture decisions documented (ADR) and aligned to the Well-Architected Framework, and guardrails validated with red-teaming β backed by AZ-305 and SC-500 certification work."