Public works wants a third-party SaaS product for online permitting. Which architecture implication should the security architect emphasize first?
Select an answer to reveal the explanation.
Short Explanation
Every new vendor is another set of keys to the city's data—architecture is not just boxes you own. Assess how that SaaS holds data, who can reach it, and how it plugs into your stack. HTTPS alone is not a vendor risk assessment.
Full Explanation
Architecture decisions that introduce third-party SaaS expand the enterprise trust boundary to include the vendor's controls, integrations, and data handling. Security implications include shared responsibility, API and identity integrations, and residual vendor risk that must be evaluated. Liability assumptions, HTTPS-only checks, or claiming only open-source creates third-party risk misstate how commercial SaaS affects municipal security architecture.