Governance principle
NRDEX is both a technology layer and a governed institutional exchange. Participation, service publication, and access must be controlled through clear ownership and approval responsibilities for the BD and BD-TEST instances.
Governance roles
-
Platform authority
Maintains platform standards, membership rules, approved instance identifiers, and operational oversight. -
Data owner
Defines the services it exposes, approves the business and legal basis, and grants access to specific consumer subsystems. -
Service consumer
Uses approved services only for authorized purposes and keeps local request logs, contact points, and operational readiness. -
Technical operator
Maintains infrastructure, certificates, connectivity, monitoring, and incident response. -
Management Security Server operator
Operates the management Security Server used for Security Server registration, management service communication, certificate registration workflows, and controlled administrative exchange between member Security Servers and the Central Server. -
Member Security Server administrator
Manages the member organization's Security Server, subsystem registration, service descriptions, access rights, certificates, logs, and local hardening.
Decision areas
- Membership approval
- Service publication approval
- Consumer authorization
- Subsystem registration approval
- Security Server registration and certificate approval
- Service publish and consume policy
- Security exception handling
- Incident escalation
- Change management
- Separation between
BD-TESTvalidation andBDproduction release
Minimum governance artifacts
- Participation agreement
- Service catalogue entry
- Access approval record
- Service publish record
- Service consume authorization record
- Audit and log retention policy
- Incident response workflow
- Security Server registration record
- Certificate lifecycle record
Management Security Server function
The management Security Server is part of the governed NRDEX control plane. It should be used to support management services such as Security Server client registration, authentication certificate registration, central service communication, and administrative workflows required by the Central Server. It does not become a broker for business data; member-to-member service traffic still flows between the participating Security Servers.
The management Security Server should be operated with strict administrator access, certificate controls, monitoring, backup, and change management because it supports trust establishment for both BD and BD-TEST.
Control objective
Governance must ensure that NRDEX does not become an uncontrolled interoperability layer. Every service relationship should remain attributable, reviewable, and policy-bound.