Institute of Computer Science
Courses.cs.ut.ee Institute of Computer Science University of Tartu
  1. Courses
  2. 2026/27 fall
  3. Secure Software Architecture (LTAT.05.044)
ET
Log in

Secure Software Architecture 2026/27 fall

  • Main
  • Lectures
  • Project
    • Week 1
    • Week 2
    • Week 3
  • References

Week 1: project setup and discovery

Goal: form the team, understand the scenario, and start from architectural drivers rather than solution ideas.

In the practical session

  • form a team of 2-3 students;
  • fork the course project starter repository on GitHub;
  • invite all team members and instructors (edurbrito-cyber, margusf, ao-cyb, martoruaascyber, ahtotruu) as collaborators;
  • create the basic project structure: /docs/, /diagrams/, /adrs/, /risk/, /api/, /ops/;
  • add a short repository README with team name, members, and current status;
  • review the official project workflow;
  • review the Citizen Services Portal scenario;
  • review the starter files and templates;
  • identify stakeholders, architectural drivers, assumptions, and open questions;
  • choose the team's current number-one driver and biggest unknown.

Deliverables due before Week 2

  • completed /docs/team_contract.adoc;
  • /docs/drivers.adoc with goals, quality attributes, constraints, assumptions, stakeholders, and open questions;
  • GitHub fork with team members and instructors added as collaborators;
  • project repository skeleton committed to the fork.

Minimum expected content in drivers.adoc

  • 5-8 business or mission goals;
  • 8-12 quality attributes or constraints;
  • stakeholder list with at least citizens, service providers, administrators/helpdesk, auditors, and external registries/agencies;
  • 5-10 assumptions that may later need validation;
  • 5-10 open questions.

Questions to answer

  • What is the system supposed to achieve for citizens?
  • Which stakeholders can make the architecture fail if their needs are ignored?
  • Which data is sensitive, regulated, or operationally critical?
  • Which external systems or organizations must the portal depend on?
  • What are the most important uncertainties today?

Quality bar

  • drivers should explain why the architecture must be shaped a certain way;
  • avoid listing only features such as login, upload, or notifications;
  • unknowns should be written as questions or risks, not hidden as assumptions.

Navigation

  • Project index
  • Next: Week 2
  • Institute of Computer Science
  • Faculty of Science and Technology
  • University of Tartu
In case of technical problems or questions write to:

Contact the course organizers with the organizational and course content questions.
The proprietary copyrights of educational materials belong to the University of Tartu. The use of educational materials is permitted for the purposes and under the conditions provided for in the copyright law for the free use of a work. When using educational materials, the user is obligated to give credit to the author of the educational materials.
The use of educational materials for other purposes is allowed only with the prior written consent of the University of Tartu.
Terms of use for the Courses environment