Someone proposes entity classes named PCI, HIPAA, and SOX for every regulated workload. What guidance should the implementer give?
Select an answer to reveal the explanation.
Short Explanation
A hospital app can be HIPAA and still be an Application. Laws are content and scope overlays, not the shape of the thing. Class-per-regulation multiplies trees until nothing shares roots.
Full Explanation
Entity classes should describe the nature of the object—organization, application, facility, vendor—not each regulation that may apply. Regulations connect through authority documents, citations, control objectives, and scoping to entities. Class-per-law designs explode when entities fall under multiple regimes and break reusable hierarchy. Citations do not replace the entity class model or generate CMDB hardware.