HTTPS is a protocol that secures HTTP communication by layering TLS/SSL to provide encryption, authentication and message integrity for web traffic. It protects user data in transit, mitigates man-in-the-middle attacks, and is the de facto standard for secure web services and APIs across public and private networks.
Use this profile to understand the building block briefly, place it in the model, and switch to the 360° assessment when needed.
Technical building block: can be automated, integrated, or operated.
Concrete cog in the system that works inside larger relationships.
HTTPS carries HTTP messages over a connection protected by TLS.
HTTPS grew from the need to protect web communication from eavesdropping and tampering. RFC 2818 described HTTP over TLS in 2000; modern TLS versions and certificate infrastructures now provide the foundation.
The client checks the server certificate, negotiates cryptographic parameters, and establishes a session key. HTTP methods, URLs, and data remain familiar while TLS encrypts and authenticates transport.
TLS cryptographically protects the transport channel.
It binds an identity to a public key.
Tampering with transmitted data becomes detectable.
HTTPS protects confidentiality and integrity in transit. Certificate validation, TLS configuration, and secure application cookies remain security responsibilities.
Where this building block is located in the topic model.
Explore how this building block connects to concepts, methods, technologies, and tools.
These sources establish the term and its professional meaning.
All direct connections of the current building block in a compact text view.
This classification shows where the building block typically matters, how demanding it is, and what kind of impact it has in the model.
The level within the organization (enterprise, domain, team) at which the AssetBlock is applied.