# SP-022 Board of Directors Room

Status: published. Release 26.02. Modified 2026-02-06. Licence: CC BY-SA 4.0.

Scope: Security architecture for protecting highly sensitive board-level communications and documents. Covers secure document distribution to board members using untrusted devices, strong authentication, cryptographic protection, non-repudiation, and resistance to endpoint compromise including trojans on personal computers.
Use when: Use this pattern when distributing highly sensitive documents to a small group of senior stakeholders who access materials from personal, unmanaged devices. Applicable for board packs, audit committee papers, remuneration committee documents, M&A due diligence materials, and other governance documents where a leak would have material regulatory, financial, or reputational consequences.
Not when: This pattern is not suitable for large user populations -- the security model relies on individual provisioning, hardware token distribution, and personal onboarding that do not scale beyond tens of users.

## Controls (17, NIST SP 800-53 ids)
- Critical (5): AC-02, AC-03, AU-10, IA-02, IA-05
- Important (10): AC-01, AC-20, AU-03, AU-09, AU-11, IA-04, IA-07, SC-08, SC-09, SC-12
- Standard (2): AU-08, SC-17
- Withdrawn from SP 800-53 by NIST: SC-09 (now in SC-08)

## What each critical control mitigates (5)
- AC-02 Account Management: T-BR-002
- AC-03 Access Enforcement: T-BR-002, T-BR-006
- AU-10 Non-repudiation: T-BR-003, T-BR-006, T-BR-010
- IA-02 Identification and Authentication (Organizational Users): T-BR-002, T-BR-004
- IA-05 Authenticator Management: T-BR-002, T-BR-004

## Threats and the controls that mitigate them (10)
- T-BR-001 Generic Trojan Horse on Board Member Endpoint: AC-20, SC-08, SC-09
- T-BR-002 Unauthorised Access to Board Documents: AC-02, AC-03, IA-02, IA-05
- T-BR-003 Board Document Leakage via Screen Capture or Photography: AU-10, AU-03, AC-20
- T-BR-004 Credential Theft or Sharing (Token Handoff): IA-02, IA-05, IA-07
- T-BR-005 Eavesdropping on Document Transport: SC-08, SC-09, SC-12
- T-BR-006 Insider Threat from Board Member or Secretary: AU-10, AU-03, AU-09, AC-03
- T-BR-007 Audit Trail Tampering by Privileged Administrator: AU-09, AU-11, AU-08
- T-BR-008 Targeted Attack on Board Portal Application: AC-01, SC-17, IA-07
- T-BR-009 Cryptographic Key Compromise: SC-12, SC-17, IA-07
- T-BR-010 Regulatory Non-Compliance from Insufficient Audit Evidence: AU-03, AU-10, AU-11, AU-08

## More
- The critical controls and what each mitigates, as JSON (a few KB): /api/v1/patterns/SP-022/crosswalk?emphasis=critical
- The same for every control, with its clauses in a framework: /api/v1/patterns/SP-022/crosswalk?framework={framework id}. Framework ids are listed in /llms.txt
- The pattern's prose, examples and references as JSON, 22 KB: /api/v1/patterns/SP-022
- Page for people: /patterns/sp-022/
- Related: SP-010 Identity Management Pattern; SP-013 Data Security Pattern; SP-014 Awareness and Training Pattern; SP-018 Information Security Management System; SP-021 Realtime Collaboration Pattern; SP-025 Advanced Monitoring and Detection

This card, the API and the page are generated from one file. Checking one against another adds no evidence.
