BIAN PLATFORM
CatalogRunFAQRepo ↗

Risk and Compliance

Information Security

sd-information-security · bian-risk-compliance

A BIAN service domain in Risk and Compliance. It applies the Administer functional pattern to the Security Policy, with the Security Policy Administrative Plan as its control record — one independent Spring Boot microservice on the platform's Cilium eBPF mesh.

View repository ↗The 162-domain platform ↗

Business DomainCompliance
Functional PatternAdminister
Asset TypeSecurity Policy
Control RecordSecurity Policy Administrative Plan

USEWhat it is used for

Representative use cases for the Information Security service domain within a BIAN-aligned core-banking landscape.

APIBIAN semantic API

The control record (Security Policy Administrative Plan) is exposed through uniform BIAN action terms. Java 21 · Spring Boot 3, OpenAPI at /swagger-ui.html, health at /actuator/health.

MethodPathBIAN action
GET/v1/service-domainService metadata
POST/v1/security-policy-administrative-plan/initiateInitiate
GET/v1/security-policy-administrative-plan/{crId}/retrieveRetrieve
PUT/v1/security-policy-administrative-plan/{crId}/updateUpdate
PUT/v1/security-policy-administrative-plan/{crId}/controlControl (suspend / resume / terminate)

INTBackend integrations

The systems and standards a real deployment of Information Security would transact with.

RUNRun it yourself

Each service domain is its own standalone Spring Boot repository — clone and run in seconds, or deploy onto Kubernetes with the bundled Helm chart behind the Cilium mesh.

# run this service domain standalone
git clone https://github.com/Sreenivas-Sadhu-Prabhakara/sd-information-security
mvn -f sd-information-security spring-boot:run
curl localhost:8080/v1/service-domain

# or deploy onto Kubernetes (Cilium eBPF mesh)
helm upgrade --install sd-information-security ./helm -n bian-risk-compliance

FAQQuestions

What is the BIAN “Administer” functional pattern?
An Administer service domain maintains and applies administrative rules, agreements or records over time. Information Security applies it to the Security Policy.
What is a BIAN service domain?
BIAN (the Banking Industry Architecture Network) decomposes a bank into independent service domains, each owning exactly one business capability. Information Security is the service domain for Compliance; it manages the Security Policy Administrative Plan and exposes it through standard BIAN action terms.
What business area does Information Security belong to?
Information Security sits in the Risk and Compliance business area — the risk, financial-crime and regulatory-compliance domains that keep the bank safe and compliant. It runs in the bian-risk-compliance namespace as one independent Spring Boot microservice.
Is Information Security production-ready?
It is an educational reference implementation: a real BIAN REST API over an in-memory store, ready to be filled with domain logic. It is not a live bank and is not affiliated with BIAN.

SEEIn the landscape

Information Security is one of 162 BIAN service domains on the platform. Explore the rest:

▚ Platform overview The Master Catalog (162 domains) This repository ↗