CISSP-ISSAP®: information systems security architecture specialist
Your security decisions must remain consistent across the information system. Connect architecture, risks and protective measures to assess trade-offs more effectively. Strengthen your expertise to design well-supported responses and engage with both technical teams and decision-makers.
- Duration
- 5 days 35 hours
- Code
- CIS02FR Code
- Certification
- CISSP® : Certified Information Systems Security Professional Certification
Accredited training for the CISSP® : Certified Information Systems Security Professional certification.
Presentation
If you hold a position of responsibility in information security, CISSP-ISSAP is a leading specialisation programme. Whether you want to advance your career, refine your skills or earn a high-level professional credential, CISSP-ISSAP concentration training is a sound choice. It demonstrates your thorough understanding of implementing information systems security architectures.
This course, intended for architects and analysts responsible for information systems security, builds on CISSP and the Common Body of Knowledge (ISC² CBK®). It develops mastery of the many areas covered by this body of knowledge and addresses threats, technologies, regulations, standards and best practices. Each CISSP-ISSAP course covers the following 6 domains:
- Domain 1: architect for governance, compliance and risk management;
- Domain 2: security architecture modelling;
- Domain 3: infrastructure security architecture;
- Domain 4: identity and access management architecture;
- Domain 5: architect for application security;
- Domain 6: security operations architecture.
By the end of this 5-day course, you will also be prepared to take the (ISC)² CISSP-ISSAP examination. You can take it at our Pearson VUE centre to earn the Certified Information Systems Security Architecture Professional credential (see the Certification tab for details).

In partnership with ISC2®, Oo2 provides official, up-to-date training content. Courses are delivered by an IT security expert authorised to teach this CISSP-ISSAP course.
Objectives
By the end of CISSP-ISSAP training, you will be able to:
- Define legal, organisational and industry requirements for designing security architecture;
- Master the stages of risk management;
- Identify the security architecture strategy to implement;
- Verify and validate architecture design;
- Establish infrastructure security requirements;
- Design defence-in-depth architecture;
- Secure shared services;
- Implement technical security controls;
- Design and integrate an infrastructure monitoring system;
- Design cryptographic solutions for infrastructure;
- Design secure network and communications infrastructure;
- Assess physical and environmental security requirements;
- Design identity and access control management and lifecycles, as well as identity and access solutions;
- Integrate the software development lifecycle (SDLC) with application security architecture;
- Determine application security needs and strategy;
- Identify common proactive application controls and security operations requirements;
- Design information security monitoring;
- Design business continuity and resilience solutions;
- Validate business continuity plan (BCP) and disaster recovery plan (DRP) architecture;
- Design cybersecurity incident response management;
- Prepare thoroughly for the official CISSP-ISSAP examination.
Program
Domain 1: governance, compliance and risk management for information systems architectures
- Applicable information security standards and regulations.
- Third-party and contractual obligations (supply chain, outsourcing, subcontracting, etc.).
- Applicable data protection standards and guidelines (GDPR).
- Designing information systems for auditability (regulatory, legislative, forensic, segregation and high-assurance system requirements, etc.).
- Coordination with external parties (law enforcement, public relations, independent experts, etc.).
- Risk identification and classification.
- Developing risk treatment recommendations (mitigation, transfer, acceptance, avoidance, etc.).
- Risk monitoring and reporting.
Domain 2: security architecture modelling
- Types and scope: enterprise, network, service-oriented architecture (SOA), cloud, IoT, industrial control systems (ICS) and Supervisory Control and Data Acquisition (SCADA).
- Frameworks: Sherwood Applied Business Security Architecture (SABSA) and Service-Oriented Modeling Framework (SOMF).
- Reference architectures and blueprints.
- Security configuration (baselines, benchmarks, profiles, etc.).
- Network configuration (physical, logical, high availability, segmentation and zones).
- Validating threat modelling outcomes (threat vectors, consequences and likelihood).
- Identifying gaps and alternative solutions.
- Independent verification and validation (tabletop exercises, modelling and simulation, manual functional reviews).
Domain 3: infrastructure security architecture
- Requirements for on-premises, cloud and hybrid systems.
- The Internet of Things (IoT) and Zero Trust.
- Network management.
- Industrial control system (ICS) security.
- Network security.
- Operating system (OS) security.
- Database security.
- Container security.
- Cloud workload security.
- Firmware security.
- User security awareness considerations.
- Securing shared services (Wi-Fi, email, voice over IP, unified communications, DNS and NTP).
- Designing boundary protection (firewalls, VPNs, air gaps, software-defined perimeters, wireless and cloud-native environments).
- Secure device management (Bring Your Own Device (BYOD), mobile devices, servers, endpoints, cloud instances and storage).
- Network visibility (sensor placement, time reconciliation, scope of control and record compatibility).
- Active and passive collection solutions (SPAN ports, port mirroring, taps, inline devices and flow logs).
- Security analytics (log collection, machine learning, User Behavior Analytics (UBA), Security Information and Event Management (SIEM)).
- Cryptographic design considerations and constraints.
- Cryptographic implementation.
- Key management lifecycle planning (generation, storage, distribution, etc.).
- Designing secure network and communications infrastructure (VPN, IPsec and TLS).
- Aligning physical security requirements with business needs (perimeter protection, internal zoning, fire suppression, etc.).
- Validating physical and environmental security controls.
Domain 4: identity and access management architecture
- Identity identification and verification.
- Assigning identifiers to users, services, processes and devices.
- Identity provisioning and deprovisioning.
- Federated and standalone trust relationships.
- Authentication methods (multifactor authentication (MFA), risk-based, location-based, knowledge-based, possession-based and characteristic-based).
- Authentication protocols and technologies (SAML, RADIUS, Kerberos, etc.).
- Access control concepts and principles.
- Access control configuration types (physical, logical and administrative).
- Authorisation processes and workflows (governance, issuance, periodic review and revocation).
- Roles, rights and responsibilities for access to systems, applications and data.
- Privileged account and permission management.
- Access control protocols and technologies (XACML and LDAP).
- Authorisation management technologies (passwords, certificates and smart cards).
- Centralised and decentralised identity and access management architectures.
- Implementing privileged access management (PAM).
- Accounting for logging, tracking and auditing.
Domain 5: application security for architecture
- Assessing code review methods (dynamic, manual, static, etc.).
- Assessing application protection needs (web application firewalls, anti-malware, secure APIs and secure SAML).
- Encryption requirements at rest, in transit and in use.
- Assessing security requirements for communications between applications and databases or other endpoints.
- Using a secure code repository.
- Application security analysis.
- Selecting cryptographic solutions for applications (cryptographic application programming interfaces, pseudorandom number generators and key management).
- Assessing whether security controls can be applied to system components.
- Identifying common proactive application controls with the Open Web Application Security Project (OWASP).
Domain 6: security operations architecture
- Security operations requirements (legal, compliance, organisational and business).
- Detection and analysis.
- Proactive, automated security monitoring and remediation (vulnerability management, compliance auditing and penetration testing).
- Integrating business impact analysis (BIA).
- Selecting recovery and viability strategies.
- Continuity and availability solutions (cold, hot and cloud backup).
- Processing agreement requirements (vendor, reciprocal, mutual, cloud and virtualisation).
- Recovery time objectives (RTOs) and recovery point objectives (RPOs).
- Establishing secure emergency communications for operations.
- Validating business continuity and disaster recovery plan architecture.
- Preparation (communications plan, incident response plan and staff training).
- Identification.
- Containment.
- Eradication.
- Recovery.
- Lessons learned analysis.
Audience
This course is intended for:
- Information security managers, architects and anyone involved in information systems security policy.
Prerequisites
CISSP-ISSAP training requires:
- A current CISSP credential and 2 years of cumulative professional experience in one or more of the 6 domains of the (ISC)² CBK.
To earn CISSP certification, you can attend our training course:
Teaching and assessment methods
- Initial skills assessment
- Training materials provided to participants
- Continuous assessment throughout the course
- End-of-course feedback questionnaire
- Combination of theory and practical application
- Attendance records
- Post-course follow-up evaluation
- Quiz / multiple-choice questions
- Practical exercises
Course highlights
An (ISC)²-authorised trainer, official course materials, comprehensive CISSP-ISSAP certification preparation, advice and assessment quizzes for each of the 6 domains covered.
Dates and sessions
Choose the date and delivery format that suit you.
No upcoming sessions are currently available.
Session alerts
Training content provided in partnership with (ISC)² ®
CISSP® and CISSP-ISSAP® are registered trademarks of the International Information Systems Security Certification.
fr
en