← Home
ISC2 · Full exam outline

ISSAP

Information Systems Security Architecture Professional

Security architecture leadership
1Architect for Governance, Compliance and Risk Management17%
1.1Determine legal, regulatory and privacy requirements
1.2Architect for organizational governance
1.3Risk management architecture
2Security Architecture Modeling15%
2.1Identify the security architecture approach and frameworks
2.2Verify and validate the design against reference models
3Infrastructure Security Architecture21%
3.1Network and communications architecture
3.2Cryptographic architecture and key management
3.3Physical and environmental security
3.4Secure operations architecture for infrastructure
4Identity and Access Management Architecture16%
4.1Identity management and provisioning architecture
4.2Authentication and credential management
4.3Authorization and access control models
4.4Federation and single sign-on
5Architect for Application Security13%
5.1Integrate security into the development lifecycle
5.2Application security controls and testing
5.3Secure interfaces, APIs and data flows
6Security Operations Architecture18%
6.1Monitoring, logging and detection architecture
6.2Incident response architecture
6.3Continuity and recovery architecture
6.4Change and configuration management
Weights are the certification body’s published values and are checked against each outline revision.