Training course
This is a free, self-paced reading course for ISSAP: Information Systems Security Architecture Professional: ISC2’s advanced credential for security architects, the people who translate business strategy, risk appetite, and regulatory obligation into the design of enterprise security itself. Where the CISSP proves breadth, the ISSAP proves you can sit between the boardroom and the engineering floor and make defensible design decisions: which framework, which trust boundaries, which cryptographic lifecycle, which identity fabric. Originally a CISSP concentration, it became a standalone advanced certification in October 2023, and you can now qualify either with a CISSP plus two years of domain experience or with seven years of cumulative experience across two or more domains.
The course is organized as one module per official exam domain, in the order ISC2 publishes them, and each module carries the domain’s published weight. It is built against the outline effective August 1, 2025, which consolidated six legacy domains into four, application security and security operations were absorbed into the surviving domains rather than standing alone, Infrastructure and System Security now carries nearly a third of the exam by itself, and AI runs throughout: trusted execution environments protecting model weights, micro-segmented AI workloads, monitoring probes for prompt injection and model evasion, identity for autonomous agents, and the NIST AI RMF applied at the blueprint level. If you have older ISSAP material on your shelf, it is describing a different exam.
What the course covers
Governance, Risk, and Compliance (GRC)
Module 1 · 21%Identifying the legal, regulatory, contractual, and privacy requirements that constrain a design, then architecting for them: monitoring and reporting pipelines, auditability and forensic readiness, segregation for high-assurance systems, risk assessment artifacts folded into the blueprint, and risk treatment advice (mitigate, transfer, accept, avoid) framed so leadership can actually sign it. The 2025 material adds vendor risk architecture for AI suppliers and the design of transparent, explainable automated decision systems.
Security Architecture Modeling
Module 2 · 22%Choosing and applying the architecture approach: scope and types including enterprise, cloud, and SOA; frameworks such as TOGAF and SABSA; reference architectures and blueprints; and threat modeling with STRIDE, CVSS, and live threat intelligence. The second half is verification and validation, functional acceptance and regression testing, gap analysis, compensating controls, tabletop exercises, modeling and simulation, peer review, and code review methodology from static and dynamic analysis through source composition analysis.
Infrastructure and System Security
Module 3 · 32%The heavyweight module, spanning deployment models across on-premises, cloud, and hybrid; IT and OT; physical security and zoning; platform security from firmware to containers; network security with segmentation, SDP, NAC, VPN and IPsec, DNS, NTP, WAF, and air gaps; storage and data repository security; cloud service models; ICS and SCADA; endpoints and BYOD; secure shared services and third-party integrations; infrastructure and content monitoring; out-of-band communications; and full cryptographic solution design covering in-transit, in-use, and at-rest implementation and the key management lifecycle.
Identity and Access Management (IAM) Architecture
Module 4 · 25%Architecting the full identity lifecycle: proofing, identifiers for users, services, processes, and devices, and joiner-mover-leaver provisioning. From there, authentication with MFA, risk-based elevation, SAML, RADIUS, Kerberos, and OAuth; authorization through segregation of duties, least privilege, RBAC and ABAC, PAM, and single sign-on models; and accounting, audit event definition, log management and integrity, analysis and reporting, and compliance with PCI-DSS, FISMA, HIPAA, and GDPR. Non-human identity for AI agents and service accounts is a new emphasis.
How to use it
Read the modules in order but weight your effort honestly: Infrastructure and System Security is 32% of the exam on its own, wider than any other module, and it is where architects with a strong governance or identity background lose the most marks. After each module, take the matching portion of the ISSAP practice exam rather than waiting until the end. ISC2 writes at this level with several defensible options and one most correct answer, so the question worth asking after every item is not whether you knew the topic but whether you could defend the choice to an architecture review board. The free ISSAP sample shows that style with no account needed.
Reading the course itself requires a free Certifym account. For exam logistics (the 125-item linear format, the three-hour window, the 700-out-of-1000 scaled pass mark, and both qualifying routes) see the ISSAP certification guide.
ISSAP Training — Information Systems Security Architecture Professional
Architect-level security across governance, modeling, infrastructure, and identity — aligned to the 2025 four-domain ISSAP refresh.
A structured training course covering the (ISC)² Information Systems Security Architecture Professional (ISSAP) Common Body of Knowledge, aligned to the 2025 four-domain refresh. Fifty-one lessons across four modules build the practitioner-level architectural judgment the exam and the role demand — from governance, risk, and compliance through security architecture modeling, infrastructure and system security architecture, and identity and access management architecture.
Module 1: Governance, Risk, and Compliance (GRC)
The architect's remit for translating law, regulation, contracts, and business risk into design decisions — and the artifacts that prove it.
- 1 What ISSAP Is 8 min Free preview
- 2 The Security Architect's Mindset 7 min 🔒
- 3 Exam Mechanics and Study Approach 6 min 🔒
- 4 Identifying Legal, Regulatory, and Industry Requirements 9 min 🔒
- 5 Third-Party and Supply Chain Obligations 8 min 🔒
- 6 Privacy Regulations and Sensitive Data Standards 8 min 🔒
- 7 Designing Resilient Solutions 7 min 🔒
- 8 Assets, Business Objectives, and Stakeholder Mapping 7 min 🔒
- 9 Designing Monitoring, Reporting, and Vulnerability Management 8 min 🔒
- 10 Designing for Auditability and Segregation 7 min 🔒
- 11 Risk Assessment Artifacts and Treatment Advisory 8 min 🔒
Module 2: Security Architecture Modeling
The frameworks, threat models, verification techniques, and validation practices that turn business risk into defensible technical design.
- 1 Scope and Types of Security Architecture 7 min 🔒
- 2 TOGAF for Security Architects 8 min 🔒
- 3 SABSA and the Business-Driven Approach 9 min 🔒
- 4 Service-Oriented Modeling and Reference Architectures 6 min 🔒
- 5 STRIDE Threat Modeling 8 min 🔒
- 6 CVSS, EPSS, and Threat Intelligence 6 min 🔒
- 7 Verifying and Validating Designs 7 min 🔒
- 8 Gaps, Alternative Solutions, and Compensating Controls 6 min 🔒
- 9 Tabletop Exercises, Peer Review, and Simulation 6 min 🔒
- 10 Code Review Methodologies 7 min 🔒
- 11 Domain 2 Review — Modeling in Practice 5 min 🔒
Module 3: Infrastructure and System Security Architecture
The largest ISSAP domain: designing the platforms, networks, storage, cloud, OT, and cryptographic infrastructure that carry the enterprise workload.
- 1 Identifying Infrastructure and System Security Requirements 7 min 🔒
- 2 Deployment Models — On-Premises, Cloud, and Hybrid 8 min 🔒
- 3 IT and Operational Technology Considerations 7 min 🔒
- 4 Physical Security — Perimeter, Zoning, and Environmental Controls 6 min 🔒
- 5 Platform Security — Virtualization and Containers 8 min 🔒
- 6 Platform Security — Firmware, OS, and Hardening 7 min 🔒
- 7 Network Security Architecture — Foundations 8 min 🔒
- 8 Network Security Architecture — Advanced Controls 7 min 🔒
- 9 Storage Security Architecture 6 min 🔒
- 10 Data Repository Security — Databases, Warehouses, and Lakes 7 min 🔒
- 11 Cloud Security Architecture in Depth 8 min 🔒
- 12 OT, ICS, and SCADA — Deeper Architectural Patterns 7 min 🔒
- 13 IoT Architecture Security 6 min 🔒
- 14 Endpoint Security — Mobile, BYOD, and EDR 7 min 🔒
- 15 Secure Shared Services and Third-Party Integrations 6 min 🔒
- 16 Infrastructure Monitoring and Content Inspection 7 min 🔒
- 17 Cryptographic Design and Key Management 9 min 🔒
Module 4: Identity and Access Management (IAM) Architecture
The identity fabric that carries every access decision in modern architectures — identity lifecycle, authentication, federation, authorization models, and accounting.
- 1 IAM Architecture Overview and Identity Lifecycle 7 min 🔒
- 2 Establishing and Verifying Identity 6 min 🔒
- 3 Identifier Assignment — Users, Services, and Devices 5 min 🔒
- 4 Provisioning and Deprovisioning — JML Workflows 6 min 🔒
- 5 Identity Management Technologies 6 min 🔒
- 6 Authentication Approaches — Factors, MFA, and Risk-Based 7 min 🔒
- 7 Authentication Protocols — SAML, OIDC, Kerberos, RADIUS 8 min 🔒
- 8 Authentication Control — Policy, LDAP, and Session Management 5 min 🔒
- 9 Trust Relationships and Federation 6 min 🔒
- 10 Authorization Concepts and Models 6 min 🔒
- 11 Authorization Approaches — RBAC, ABAC, PBAC, and Delegation 7 min 🔒
- 12 Identity Accounting — Audit, Compliance, and SIEM Integration 5 min 🔒
Frequently asked questions about the ISSAP training course
Is the ISSAP training course free?
Yes. The course costs nothing to read and opens once you are signed in to a free Certifym account, no payment and no card.
How is the course structured?
One module per official ISSAP exam domain, in ISC2’s published order, with each module weighted to the domain’s published percentage. There are four modules, because the outline effective August 1, 2025 consolidated the six legacy domains into four.
Does this replace ISC2’s official training?
No. ISC2 publishes the authoritative ISSAP exam outline and sells official training against it. This course is an independent study companion written from the publicly available outline, meant to be read alongside practice questions. It is not an ISC2 product and carries no ISC2 endorsement.
Do I need the CISSP before starting?
Not to read the course. To hold the credential there are two routes: a CISSP plus two years of experience in the ISSAP domains, or seven years of cumulative experience in two or more domains without the CISSP. The second route only opened when ISSAP became a standalone certification in October 2023. The course assumes you already design or review enterprise systems.
What should I do after finishing the course?
Move to the ISSAP practice exam, which is stratified to the official weights so nearly a third of every attempt lands in Infrastructure and System Security. Work until you clear roughly 70% in each domain separately rather than on the total, then book with Pearson VUE.
Is the course current with the latest ISSAP outline?
It is built against the four-domain outline effective August 1, 2025, not the retired six-domain structure, application security and security operations no longer stand alone, the weights have moved, and the AI content is new. ISC2 can revise the outline at any time; download the current one from isc2.org before you schedule.
Trademark notice & independence. Certifym.net is operated by Certifym Exam Services, LLC and is not affiliated with, endorsed by, or sponsored by ISC2, Inc. ISC2®, CISSP®, ISSAP®, and CBK® are registered marks of ISC2, Inc. Certification names and marks are used solely to identify the certification for which these independent study materials are designed. The ISSAP exam outline and its domain structure are the property of ISC2, Inc.; candidates should download the official, current exam outline directly from isc2.org.
All course content, questions, answers, and explanations on Certifym are original content created for study purposes. They are not actual ISC2 training materials or examination questions and are not represented as such. Studying with these materials does not guarantee a passing result on any live certification exam. Exam requirements, format, domain weights, pricing, and eligibility policies are set by ISC2 and may change; always verify current details on isc2.org before scheduling your exam.
