ZETLAN TECHNOLOGIES
Course Categories 172+
Cloud & Infrastructure 7
Networking 8
Virtualisation 5
IT Security 10
CyberSecurity & Mgmt 14
Software Development 16
Web Dev & Database 27
Data Science & AI 14
Mobile, Testing & Games 22
Design & Creative 49
Navigation
Home Business About Us Contact Us All Courses FAQ & Help
Contact Us
+91 8680961847 +91 8680961847 (WhatsApp) info@zetlantechnologies.com
Browse by Domain
Cloud & Infrastructure 7
Networking 8
Virtualisation 5
IT Security 10
CyberSecurity & Mgmt 14
Software Development 16
Web Dev & Database 27
Data Science & AI 14
Mobile, Testing & Games 22
Design & Creative 49
2000+ Courses · 15+ Technology Domains
Microsoft Cisco AWS EC-Council View All Courses
Home  /  ISC2 Certifications  /  ISSAP
🏗️ CISSP Concentration · Advanced Level

ISC2 Information Systems Security
Architecture Professional (ISSAP)

Demonstrate elite expertise in designing and analysing security solutions as a chief security architect. The ISSAP is the ISC2 concentration for CISSP holders who define and lead security architecture across the enterprise.

Security Architecture CISSP Concentration Enterprise Architecture Risk Management IAM Design Application Security
Enroll Now
Architecture ModellingFrameworks, blueprints & design validation
Infrastructure SecurityDefence-in-depth & boundary protection
IAM ArchitectureIdentity lifecycle & access design
Application SecuritySDLC integration & secure APIs
125
Exam Questions
3 Hrs
Duration
Active CISSP
Prerequisite
6
Domains
Why It's Valuable

The Elite Security Architecture Credential

ISSAP distinguishes security architects who bridge the gap between executive strategy and technical implementation, commanding premium recognition in enterprise environments.

Elite
Architect Level
ISSAP proves elite architectural expertise beyond the CISSP, positioning you as the go-to security architect in enterprise environments.
Trending
C-Suite
Bridge Role
ISSAP holders operate between C-suite leadership and technical security programme implementation.
6
Architecture Domains
Covers governance, risk, infrastructure, cryptography, IAM and application security architecture.
Trending
CISSP
Required Prereq.
An active CISSP certification is required, making ISSAP an elite next step for established professionals.
Certification

ISC2 Information Systems Security Architecture Professional (ISSAP)

ISSAP — Information Systems Security Architecture Professional

The ISSAP is a CISSP concentration credential ideal for chief security architects, analysts and professionals who play a key role in developing, designing and analysing security solutions. You excel at providing risk-based guidance to senior management in pursuit of organisational goals.

Prerequisite: Active CISSP certification in good standing. Experience: Two years of cumulative paid work experience in one or more of the six ISSAP domains. Ideal for: System Architect, Chief Technology Officer, System and Network Designer, Business Analyst, Chief Security Officer.

Exam Overview

ISSAP — Security Architecture Professional Exam Details

Language
English
Duration
180 Minutes
Total Questions
125
Passing Score
700 out of 1000
Format
Multiple Choice
Prerequisite
Active CISSP Certification

Exam details may change. Refer to the official ISC2 website for the latest information on pricing and policies.

Course Content

Complete ISSAP Curriculum

Click any domain to expand and explore the topics covered in detail.

01
Architect for Governance, Compliance and Risk Management
6 Topics
Determine applicable information security standards, guidelines and legal requirements
Identify third-party and contractual obligations including supply chain and outsourcing
Design for auditability: regulatory, legislative and forensic requirements
Coordinate with external entities such as law enforcement and independent assessors
Identify, classify and assess risks and recommend treatment strategies
Implement risk monitoring and reporting frameworks
02
Security Architecture Modelling
5 Topics
Identify security architecture approach: enterprise, SOA, cloud, IoT, ICS/SCADA
Apply frameworks such as SABSA and SOMF for architecture design
Define reference architectures, blueprints and security configuration baselines
Design network configuration: physical, logical, high availability and segmentation
Verify and validate design through FAT, regression and IV&V methods
03
Infrastructure Security Architecture
6 Topics
Develop infrastructure security requirements for on-premise, cloud and hybrid environments
Design defence-in-depth architecture covering network, OS, database and container security
Secure shared services: wireless, VoIP, DNS, NTP and unified communications
Design boundary protection: firewalls, VPNs, airgaps and cloud-native controls
Implement secure device management for BYOD, mobile, server and endpoint devices
Design and integrate infrastructure monitoring using SIEM and security analytics
04
Cryptography and Network Security Architecture
5 Topics
Design infrastructure cryptographic solutions considering constraints and lifecycle
Determine cryptographic implementation for data in transit, in use and at rest
Plan key management lifecycle: generation, storage and distribution
Design secure network and communication infrastructure: VPN, IPSec, TLS
Evaluate physical and environmental security requirements and validate controls
05
Identity and Access Management (IAM) Architecture
5 Topics
Design identity management lifecycle: establishment, provisioning and de-provisioning
Design access control: discretionary/mandatory, separation of duties, least privilege
Design centralized IAM architecture: cloud-based, on-premise and hybrid
Define authentication methods: MFA, risk-based, SAML, RADIUS, Kerberos
Implement Privileged Access Management (PAM) and decentralised IAM solutions
06
Architect for Application Security
5 Topics
Integrate SDLC with application security: code review, WAF and secure API design
Determine encryption requirements for applications at rest, in transit and in use
Review security of applications: custom, COTS, in-house and cloud-based
Determine application cryptographic solutions and key management strategies
Identify common proactive controls using OWASP and security assessment techniques
07
Security Operations Architecture
5 Topics
Gather security operations requirements: legal, compliance and business needs
Design information security monitoring: SIEM, threat intelligence and UEBA
Design Business Continuity and resiliency solutions with BIA and recovery strategies
Validate BCP/DRP architecture and establish RTO/RPO objectives
Design Incident Response management: preparation, identification and recovery phases
FAQs

Frequently Asked Questions

What is the ISSAP certification?
The ISSAP (Information Systems Security Architecture Professional) is an ISC2 CISSP concentration that validates elite expertise in security architecture. It is designed for professionals who develop, design and analyse security solutions and provide strategic risk-based guidance to senior management.
Who is eligible for the ISSAP?
Candidates must hold an active CISSP certification in good standing and have two years of cumulative paid work experience in one or more of the six ISSAP domains. The ISSAP is ideal for Security Architects, Chief Security Officers, System and Network Designers and Business Analysts.
What is the ISSAP exam format?
The ISSAP exam consists of 125 multiple choice questions to be completed within 180 minutes. A score of 700 out of 1000 is required to pass. The exam is administered through Pearson VUE.
How does ISSAP differ from CISSP?
While CISSP provides broad coverage across eight security domains, ISSAP is a deep-dive concentration focusing specifically on security architecture. CISSP is the prerequisite; ISSAP demonstrates advanced mastery in architectural design and analysis.
What roles does ISSAP support?
ISSAP supports senior roles such as Chief Security Architect, Chief Technology Officer, Enterprise Security Architect, System and Network Designer and Business Analyst within information security teams.
Does ISSAP need to be renewed?
Yes — the ISSAP is renewed alongside your CISSP every three years. You must earn Continuing Professional Education (CPE) credits and pay the Annual Maintenance Fee (AMF) to maintain both credentials.
Get Started

Distinguish Yourself as an Elite Security Architect

Join Zetlan Technologies' ISSAP programme and master the advanced architectural skills that position you as a strategic security leader in any enterprise environment.

Zetlan Technologies
Online — Replies in minutes
👋 Hi! Welcome to Zetlan Technologies.

Interested in ISSAP — ISC2 Information Systems Security Architecture Professional? Ask us anything!
Just now
Course Details? Batch Timings? Exam Details
Open WhatsApp Chat
Your info is safe with us
💬 Chat with us!