Bus access can have secure or non-secure attribution which follows the transaction through the system.
Non-secure peripherals use non-secure DMA bus transactions. Secure peripherals have configurable DMA security and can generate either secure or non-secure DMA bus transactions. The peripheral security is configured using SPU — System protection unit.
For Arm Cortex CPUs, see the Arm TrustZone architecture document for more details on security.