Snapshot
Enterprise architecture, interoperability, service governance, security, privacy, accessibility, procurement and EU institutional constraints.
Module status
- •Track: Shared ICT foundations
- •Last verified: 2026-08-11
- •Scope: Independent EPSOHQ training mapped to the notice duties; official sources prevail.
Architecture before products
An AD7 administrator must translate institutional needs into services that remain supportable, secure and interoperable. Start with capabilities, information flows, service levels, constraints and risks. Product selection comes after the target architecture and evaluation criteria. A design that is technically elegant but impossible to operate, procure, audit or exit is incomplete.
Architecture decisions should record context, options, the chosen decision, consequences and review triggers. Reversibility matters. Interfaces and portable data formats reduce coupling. A technology radar separates adopted, trial, assessed and held technologies so experimentation does not silently become production architecture.
Interoperability and public-sector constraints
The Interoperable Europe Act creates a framework for cross-border interoperability of public-sector network and information systems. Interoperability has legal, organisational, semantic and technical layers. An API alone does not solve different legal bases, process ownership or data meanings.
Accessibility belongs in acceptance criteria. Security and data protection belong in design. Procurement needs measurable requirements, fair evaluation and an exit path. Records, transparency and auditability affect logs, retention and decision evidence.
Security and privacy by design
Use risk to select controls. Defence in depth combines identity, endpoints, networks, applications, data, monitoring and recovery. Least privilege limits access to what a subject needs. Separation of duties reduces the chance that one identity can initiate, approve and conceal a sensitive action.
Privacy by design means defining purpose, legal basis, minimisation, retention, access, transfers and data-subject rights before implementation. Encryption protects confidentiality but does not by itself establish lawful processing. Pseudonymisation reduces linkability but remains personal-data processing when re-identification remains possible.
Service governance
Define service owner, product owner, technical owner and data owner. Set service-level indicators before service-level objectives. Track user outcomes alongside availability. A service can be technically available yet unusable because authentication, latency or a critical dependency fails.
Every production service needs monitoring, incident roles, backup and restore evidence, continuity assumptions, supplier escalation and a decommissioning plan. Change approval should be proportional to risk. Standard, low-risk changes can be pre-authorised; emergency changes still need traceability and retrospective review.
Core source set
- •Interoperable Europe Act — Regulation (EU) 2024/903
- •NIS2 — Directive (EU) 2022/2555
- •GDPR — Regulation (EU) 2016/679
- •Web Accessibility Directive — Directive (EU) 2016/2102
- •European Commission PM² methodology — PM² portal