Training course
This is a free, self-paced reading course for ISSAP: Information Systems Security Architecture Professional: ISC2’s advanced credential for security architects, the people who translate business strategy, risk appetite, and regulatory obligation into the design of enterprise security itself. Where the CISSP proves breadth, the ISSAP proves you can sit between the boardroom and the engineering floor and make defensible design decisions: which framework, which trust boundaries, which cryptographic lifecycle, which identity fabric. Originally a CISSP concentration, it became a standalone advanced certification in October 2023, and you can now qualify either with a CISSP plus two years of domain experience or with seven years of cumulative experience across two or more domains.
The course is organized as one module per official exam domain, in the order ISC2 publishes them, and each module carries the domain’s published weight. It is built against the outline effective August 1, 2025, which consolidated six legacy domains into four, application security and security operations were absorbed into the surviving domains rather than standing alone, Infrastructure and System Security now carries nearly a third of the exam by itself, and AI runs throughout: trusted execution environments protecting model weights, micro-segmented AI workloads, monitoring probes for prompt injection and model evasion, identity for autonomous agents, and the NIST AI RMF applied at the blueprint level. If you have older ISSAP material on your shelf, it is describing a different exam.
What the course covers
Governance, Risk, and Compliance (GRC)
Module 1 · 21%Identifying the legal, regulatory, contractual, and privacy requirements that constrain a design, then architecting for them: monitoring and reporting pipelines, auditability and forensic readiness, segregation for high-assurance systems, risk assessment artifacts folded into the blueprint, and risk treatment advice (mitigate, transfer, accept, avoid) framed so leadership can actually sign it. The 2025 material adds vendor risk architecture for AI suppliers and the design of transparent, explainable automated decision systems.
Security Architecture Modeling
Module 2 · 22%Choosing and applying the architecture approach: scope and types including enterprise, cloud, and SOA; frameworks such as TOGAF and SABSA; reference architectures and blueprints; and threat modeling with STRIDE, CVSS, and live threat intelligence. The second half is verification and validation, functional acceptance and regression testing, gap analysis, compensating controls, tabletop exercises, modeling and simulation, peer review, and code review methodology from static and dynamic analysis through source composition analysis.
Infrastructure and System Security
Module 3 · 32%The heavyweight module, spanning deployment models across on-premises, cloud, and hybrid; IT and OT; physical security and zoning; platform security from firmware to containers; network security with segmentation, SDP, NAC, VPN and IPsec, DNS, NTP, WAF, and air gaps; storage and data repository security; cloud service models; ICS and SCADA; endpoints and BYOD; secure shared services and third-party integrations; infrastructure and content monitoring; out-of-band communications; and full cryptographic solution design covering in-transit, in-use, and at-rest implementation and the key management lifecycle.
Identity and Access Management (IAM) Architecture
Module 4 · 25%Architecting the full identity lifecycle: proofing, identifiers for users, services, processes, and devices, and joiner-mover-leaver provisioning. From there, authentication with MFA, risk-based elevation, SAML, RADIUS, Kerberos, and OAuth; authorization through segregation of duties, least privilege, RBAC and ABAC, PAM, and single sign-on models; and accounting, audit event definition, log management and integrity, analysis and reporting, and compliance with PCI-DSS, FISMA, HIPAA, and GDPR. Non-human identity for AI agents and service accounts is a new emphasis.
How to use it
Read the modules in order but weight your effort honestly: Infrastructure and System Security is 32% of the exam on its own, wider than any other module, and it is where architects with a strong governance or identity background lose the most marks. After each module, take the matching portion of the ISSAP practice exam rather than waiting until the end. ISC2 writes at this level with several defensible options and one most correct answer, so the question worth asking after every item is not whether you knew the topic but whether you could defend the choice to an architecture review board. The free ISSAP sample shows that style with no account needed.
Reading the course itself requires a free Certifym account. For exam logistics (the 125-item linear format, the three-hour window, the 700-out-of-1000 scaled pass mark, and both qualifying routes) see the ISSAP certification guide.
What ISSAP Is
The Information Systems Security Architecture Professional — ISSAP — is one of ISC2's three advanced concentrations built on top of the CISSP. Where the CISSP validates broad managerial and technical mastery of information security, the ISSAP narrows the lens to a single discipline: designing the security architecture of enterprise systems. That includes on-premises networks, cloud and hybrid environments, industrial and operational technology, and the identity fabric that stitches everything together.
The credential is aimed at practitioners who have moved past hands-on operations and are now responsible for shaping how security is embedded in systems from the earliest design decisions. That means working with business stakeholders to understand mission and risk, choosing frameworks and reference architectures, modeling threats, and specifying the controls that engineering teams then build. It also means giving management risk-based guidance, not just technical recommendations.
Who ISSAP is for
ISC2 offers two eligibility paths. The traditional path requires an active CISSP in good standing plus two years of cumulative full-time experience in one or more of the current ISSAP domains. A newer path, opened in late 2023 and refined in 2025, allows candidates without the CISSP to qualify with seven years of cumulative full-time experience in two or more of the ISSAP domains — a post-secondary degree in a related field or another ISC2-approved credential can substitute for one year of that requirement.
The typical ISSAP holder has titles such as Security Architect, Chief Security Architect, Enterprise Security Architect, or Principal Security Consultant. Many are consultants who design security architectures for multiple client organizations. Others sit inside enterprise architecture teams and act as the security voice in every major solution design.
What the exam covers (as of August 1, 2025)
The 2025 refresh consolidated the previous six domains into four, and shifted more weight toward infrastructure and identity — the two areas where architects spend the most time in modern hybrid and cloud environments. The current domains and weights are:
- Domain 1: Governance, Risk, and Compliance (GRC) — 21%
- Domain 2: Security Architecture Modeling — 22%
- Domain 3: Infrastructure and System Security Architecture — 32%
- Domain 4: Identity and Access Management (IAM) Architecture — 25%
Notice what happened to the old topics. Application Security is now embedded inside Infrastructure and System Security, not a domain of its own. Security Operations Architecture is largely absorbed into Infrastructure monitoring and IAM accounting. Cryptography moved under Infrastructure as well. The exam still expects you to understand these topics — the outline just organizes them differently.
Format and scoring
The exam is linear (not adaptive, unlike the CISSP): 125 multiple-choice items, 3 hours, delivered in English at Pearson VUE test centers. The passing score is 700 out of 1000 on a scaled system — that means raw percentages are not directly comparable across candidates because item difficulty is weighted. As a working benchmark, most study guides suggest aiming for roughly 80% or better on practice materials to be comfortable on exam day.
Retake rules: 30 days after a first failure, 60 days after a second, 90 days after a third, with a maximum of four attempts per credential in any twelve-month period.
What this course does
This course is built to the 2025 exam outline, not the legacy six-domain version. Every lesson maps to a specific subdomain or subtopic in the current CBK. The intent is to give you an architect's working vocabulary and the pattern library you need to reason about design decisions — not to memorize facts. On the exam and on the job, the ISSAP tests judgment: given a business context, a set of constraints, and a threat model, what is the best architectural choice?
Pair this training with hands-on architecture work, the practice exam bank, and at least one full read of the current ISSAP Exam Outline. The reference frameworks — SABSA, TOGAF, NIST SP 800-53 and 800-207, ISO 27001, the Cloud Security Alliance guidance, and OWASP — are the vocabulary of the discipline. Fluency there is what separates a solid candidate from someone who is guessing.
Frequently asked questions about the ISSAP training course
Is the ISSAP training course free?
Yes. The course costs nothing to read and opens once you are signed in to a free Certifym account, no payment and no card.
How is the course structured?
One module per official ISSAP exam domain, in ISC2’s published order, with each module weighted to the domain’s published percentage. There are four modules, because the outline effective August 1, 2025 consolidated the six legacy domains into four.
Does this replace ISC2’s official training?
No. ISC2 publishes the authoritative ISSAP exam outline and sells official training against it. This course is an independent study companion written from the publicly available outline, meant to be read alongside practice questions. It is not an ISC2 product and carries no ISC2 endorsement.
Do I need the CISSP before starting?
Not to read the course. To hold the credential there are two routes: a CISSP plus two years of experience in the ISSAP domains, or seven years of cumulative experience in two or more domains without the CISSP. The second route only opened when ISSAP became a standalone certification in October 2023. The course assumes you already design or review enterprise systems.
What should I do after finishing the course?
Move to the ISSAP practice exam, which is stratified to the official weights so nearly a third of every attempt lands in Infrastructure and System Security. Work until you clear roughly 70% in each domain separately rather than on the total, then book with Pearson VUE.
Is the course current with the latest ISSAP outline?
It is built against the four-domain outline effective August 1, 2025, not the retired six-domain structure, application security and security operations no longer stand alone, the weights have moved, and the AI content is new. ISC2 can revise the outline at any time; download the current one from isc2.org before you schedule.
Trademark notice & independence. Certifym.net is operated by Certifym Exam Services, LLC and is not affiliated with, endorsed by, or sponsored by ISC2, Inc. ISC2®, CISSP®, ISSAP®, and CBK® are registered marks of ISC2, Inc. Certification names and marks are used solely to identify the certification for which these independent study materials are designed. The ISSAP exam outline and its domain structure are the property of ISC2, Inc.; candidates should download the official, current exam outline directly from isc2.org.
All course content, questions, answers, and explanations on Certifym are original content created for study purposes. They are not actual ISC2 training materials or examination questions and are not represented as such. Studying with these materials does not guarantee a passing result on any live certification exam. Exam requirements, format, domain weights, pricing, and eligibility policies are set by ISC2 and may change; always verify current details on isc2.org before scheduling your exam.
