> For the complete documentation index, see [llms.txt](https://stephen-tsoi.gitbook.io/stephen-tsoi-docs/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://stephen-tsoi.gitbook.io/stephen-tsoi-docs/event-driven-architecture/event-governance-the-foundation-of-successful-event-driven-architecture/day-10-14-event-security-control.md).

# Day 10/14 Event Security Control

Day 10 of 14: A comprehensive security framework for EDA, breaking down event mesh isolation, robust client authentication, and PII payload encryption.

**Events are crucial digital assets**, housing personal and confidential information. This includes sensitive details like account numbers, balances on statements, and personal data in customer profiles. Implementing suitable event control measures is paramount to safeguarding these assets. It is vital to securely transmit events within a protected environment and limit access based on defined permissions. Event control encompasses the following categories:

**Event Mesh Control**

1. Utilizing a separated event bus to accommodate internal and external usage
2. Employing a separate VPN or instance to accommodate partner, non-login user, and log in user even if there is information overlap.
3. Implementing robust security authentication between event buses, such as utilizing certification for connections and enabling SSL encryption.

**Event Routing and Filtering**

1. Only route essential events in the event mesh.
2. Only route essential events in VPN or instance.

**Event Accessibility**

1. Disable default and basic authentication
2. Restrict client connections to the event bus via Kerberos, OAuth, or Certification authentication only.
3. Implement SSL encryption for connections between clients and the event bus or within the event mesh.
4. Establish precise access permissions at the VPN, Topic, and Queue levels.
5. Encrypt the payload containing Personally Identifiable Information (PII).

## 🚀 Let's Connect Beyond GitBook!

If you found this article helpful, you can find more of my technical insights, daily discussions, and deep dives across these platforms:

* **Read more of my work:** Check out my articles on [dev.to](https://dev.to/stephen_tsoi_5b2c4055f3a9) and [Hashnode](https://stephentsoi.hashnode.dev/).
* **Join the daily conversation:** Connect with me directly on [LinkedIn](https://www.linkedin.com/in/stephen-tsoi-16309730/).

***

#### 📬 Stay Ahead of the Curve

Enjoyed this piece? I break down complex technical topics into bite-sized, actionable insights every week.

👉 **Subscribe to my** [**LinkedIn Newsletter**](https://www.linkedin.com/build-relation/newsletter-follow?entityUrn=7487299517642612736) to never miss an update and get the latest articles delivered straight to your feed!


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://stephen-tsoi.gitbook.io/stephen-tsoi-docs/event-driven-architecture/event-governance-the-foundation-of-successful-event-driven-architecture/day-10-14-event-security-control.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
