E-commerce Platform (PCI DSS Relevant)
Dexfense ReviewedOnline retail architecture covering web storefront, product and order APIs, customer database, CDN, WAF and PCI DSS-relevant audit logging.
Overview
Represents a standard e-commerce stack handling product browsing, cart management and order processing. Includes a web storefront, REST APIs, a SQL order and customer database, NoSQL product and session cache, CDN for media assets, load balancing and DDoS-protected DNS, WAF, customer OAuth authentication, MFA for staff accounts, centralised audit logging and backup systems. Card payment is delegated to a PCI-certified PSP; the card data environment is out of scope.
Intended for
E-commerce security engineers, PCI DSS assessors and development leads at retail companies.
Architecture Assumptions
This template assumes the following conditions. If your environment differs, use Remix to adapt the component selection.
- Card payment is handled by a PCI-compliant payment service provider; card data does not touch the application directly
- Checkout flow is internet-facing and protected by WAF and DDoS mitigation
- Admin and staff accounts require MFA; admin panel access is restricted
- Order and customer data is encrypted at rest and backed up regularly
Out of Scope
- Payment service provider and card data environment are explicitly out of scope
- Fraud detection and transaction monitoring engines are not modelled
- Assumes cloud-native deployment; on-premises retail POS systems are not included
Architecture Components14 components selected
Web & APIs
Web Servers
Public-facing web application servers
API Services
API endpoints for application integration
CDN
Content Delivery Networks for distributed hosting
Databases
SQL Databases
Relational databases holding structured data
NoSQL Databases
Non-relational databases for unstructured data
Storage
Cloud Storage
Cloud-based object or file storage
Backup Systems
Data backup and recovery systems
Network
Load Balancers
Traffic distribution systems
WAF
Web Application Firewall
DNS Services
Domain name resolution services
Auth & IAM
OAuth/OIDC
Open authorization and identity protocols
Multi-Factor Auth
Additional authentication verification layer
Monitoring
Logging Systems
Centralized log collection and management
Cloud
AWS Infrastructure
Amazon Web Services infrastructure
Security Preview
Based on this architecture's component selection
Indicative Risk Score
59/100
11 techniques identified
2 Critical · 2 High
Top Attack Techniques
- CriticalT1068Exploitation for Privilege Escalation
- CriticalT1486Data Encrypted for Impact
- HighT1190Exploit Public-Facing Application
- HighT1070Indicator Removal on Host
- MediumT1078Valid Accounts
Top Recommended Controls
- 1Implement Web Application Firewall (WAF) and regular security testing
- 2Implement comprehensive cloud security posture management
- 3Focus on Data Protection as your highest priority security initiative
The full defense plan — mitigations, detection methods, NIST CSF 2.0 mapping and exportable report — is available when you use this architecture in the planner.
Remix copies the components so you can add or remove items before generating your assessment.
Dexfense does not scan your systems. This template identifies threats and controls relevant to this architecture. Product and version validation is still required.