SecLeaderAcademy
← Home
ISC2 · Full exam outline
ISSAP
Information Systems Security Architecture Professional
Security architecture leadership
1
Architect for Governance, Compliance and Risk Management
17%
1.1
Determine legal, regulatory and privacy requirements
1.2
Architect for organizational governance
1.3
Risk management architecture
2
Security Architecture Modeling
15%
2.1
Identify the security architecture approach and frameworks
2.2
Verify and validate the design against reference models
3
Infrastructure Security Architecture
21%
3.1
Network and communications architecture
3.2
Cryptographic architecture and key management
3.3
Physical and environmental security
3.4
Secure operations architecture for infrastructure
4
Identity and Access Management Architecture
16%
4.1
Identity management and provisioning architecture
4.2
Authentication and credential management
4.3
Authorization and access control models
4.4
Federation and single sign-on
5
Architect for Application Security
13%
5.1
Integrate security into the development lifecycle
5.2
Application security controls and testing
5.3
Secure interfaces, APIs and data flows
6
Security Operations Architecture
18%
6.1
Monitoring, logging and detection architecture
6.2
Incident response architecture
6.3
Continuity and recovery architecture
6.4
Change and configuration management
Weights are the certification body’s published values and are checked against each outline revision.