Prepare for ISSAP by connecting organizational requirements to security design decisions. Use the four-domain map and the worked example to check whether a proposed design meets every stated requirement.
What the ISSAP credential covers
The Information Systems Security Architecture Professional (ISSAP) focuses on designing security solutions and giving management risk-based guidance. Use the outline effective from 1 August 2025.
The current outline covers four domains. Use the weights below to check coverage alongside your own knowledge gaps; they are not exact question counts or a compulsory study timetable.
ISC2 also notes that the outline embeds AI security considerations across the domains, reflecting environments where AI is both a defensive asset and a protected surface. You will see that framing in ISC2's own outline commentary rather than as a separate fifth domain.
| Domain | Weight |
|---|---|
| 1. Governance, Risk, and Compliance (GRC) | 21% |
| 2. Security Architecture Modeling | 22% |
| 3. Infrastructure and System Security | 32% |
| 4. Identity and Access Management (IAM) Architecture | 25% |
Sources: ISSAP official English exam outline — Information Systems Security Architecture Professional Certification Exam Outline, effective August 1, 2025; ISSAP Certification Exam Outline Summary — ISC2 certification outline page
Experience requirements and eligibility
ISC2 offers two experience routes to certification. CISSP is required for one route, but not for both.
One route requires CISSP in good standing plus two cumulative years of full-time experience in at least one current ISSAP domain.
The alternative requires seven cumulative years of full-time experience across at least two current domains. Under this route, a qualifying degree or approved additional credential may satisfy one year; only one year can be waived.
Qualifying part-time work and internships may also count. Review the current requirements and prepare your experience documentation for the certification application.
Sources: ISSAP Certification Exam Outline Summary — ISC2 certification outline page; ISSAP official English exam outline — Information Systems Security Architecture Professional Certification Exam Outline, effective August 1, 2025; Endorsement | Online Endorsement Application | ISC2 — ISC2 endorsement page
Exam format, length and scoring
ISSAP allows three hours for 125 items in English at Pearson VUE testing centers.
The dated outline PDF lists multiple-choice questions. The current ISSAP outline webpage also lists advanced item types; check the current exam information and appointment instructions when preparing.
The passing grade is 700 out of 1000, a scaled score. It is not a raw 70% or a published number of correct answers.
An unofficial result is normally provided at checkout, followed by official notification. ISC2 does not report numerical scores. Unsuccessful candidates receive domain proficiency feedback. Results can be delayed, so avoid planning around a guaranteed notification time.
Sources: ISSAP Certification Exam Outline Summary — ISC2 certification outline page; ISSAP official English exam outline — Information Systems Security Architecture Professional Certification Exam Outline, effective August 1, 2025; What To Do After Your ISC2 Certification Exam — ISC2 after-your-exam page
Domain 1: Governance, risk and compliance
This domain tests whether you can identify legal, regulatory, organizational and industry requirements, then architect for governance, auditability and risk treatment against them.
The outline splits this domain into two objectives. First, identify requirements: applicable security standards, third-party and contractual obligations such as supply chain and outsourcing, sensitive-data and privacy regulations, and resilient solutions. Second, architect for GRC: identify key assets, business objectives and stakeholders; design monitoring and reporting; design for auditability; incorporate risk assessment artifacts; and advise on risk treatment, meaning mitigate, transfer, accept or avoid.
Practise tracing a proposed design to its stated requirements. In the fictional exercise below, all three requirements must be met; an improvement in one area cannot compensate for missing another.
Practice exercise
A fictional organization, Meridian Retail, sets three requirements for its new customer-data platform: (1) all customer data must remain stored in Region A; (2) audit records must remain retrievable for at least 90 days; (3) every privileged administrative change must have a recorded approval. Assume this design evidence is accurate and complete, and assume no other requirements apply. Four designs are proposed: Option A stores data in Region A, retains audit records 30 days, records approvals. Option B stores data in Region B, retains audit records 180 days, records approvals. Option C stores data in Region A, retains audit records 90 days, records no approval. Option D stores data in Region A, retains audit records 180 days, records approvals. Which option meets all three requirements?
Show answer
Option D.
Check each option against all three constraints. Option A satisfies residency and approval but retains audit records for only 30 days, failing the 90-day requirement. Option B satisfies retention and approval but stores data in Region B, failing residency. Option C satisfies residency and retention but records no approval, failing the third requirement. Option D meets all three: Region A storage, 180 days of retrievability (which exceeds the 90-day floor) and recorded approvals. Note that B's 180-day retention, a strong feature, cannot compensate for its residency failure; each requirement must be met independently. These are supplied organizational requirements for this exercise, not universal legal mandates or recommended retention periods.
Domain 2: Security architecture modeling
This domain covers choosing a security architecture approach and verifying and validating the resulting design, including threat modeling results and code review methods.
On the approach side, the outline lists scope and types (enterprise, cloud, network, service-oriented architecture), frameworks, reference architectures and blueprints, and threat modeling frameworks. Named examples include TOGAF, SABSA and the service-oriented modeling framework on the architecture side, and STRIDE, CVSS and threat intelligence on the threat side. Treat these names as preparation priorities: the outline identifies them as topics, so know what each one is and when it applies, but the outline does not prescribe one as universally correct.
On verification, the outline expects you to work with threat modeling results such as threat vectors, impact and probability; identify gaps and alternative solutions, mitigations or compensating controls; and use internal or external third-party validation such as tabletop exercises, modeling and simulation, manual review and peer review. It also lists code review methodologies: dynamic, manual, static and source composition analysis.
A useful study habit is to practice writing architecture decisions as justifications: state the requirement driving the decision, the decision itself, and at least one alternative you rejected and why. This mirrors the domain's own structure of choosing an approach, then verifying and validating the design against it.
Domain 3: Infrastructure and system security architecture
Review infrastructure requirements, control architecture and cryptographic design across the technologies listed in the outline.
The first objective is identifying requirements: deployment model (on-premises, cloud-based, hybrid), IT and operational technology, physical security including perimeter protection, zoning and fire suppression, infrastructure and system monitoring, cryptography, and application security items such as a Requirements Traceability Matrix, security architecture documentation and secure coding.
The second objective, architecting infrastructure and system security, is the longest topic list in the outline. Group your review rather than memorizing the list linearly:
The third objective covers cryptographic solutions: design considerations and constraints such as technologies, lifecycle, computational capabilities and algorithms; implementation across data in transit, in use and at rest; and planning the key management lifecycle from generation through storage to distribution.
For practice, sketch a scenario’s data flows and identify the control families that could apply at each boundary. Justify each proposed choice against a stated requirement.
- Physical security: cameras, doors, system controllers.
- Platform security: physical, virtual, container, firmware, operating systems.
- Network security: wired and wireless, firewalls, VPN and IPsec, NAC, DNS, NTP, VoIP, WAF, software-defined perimeters, airgaps, IoT and management networks.
- Storage and data repositories: DAS, SAN, NAS, archival and removable media, encryption, access control, redaction, masking.
- Cloud models: public and private IaaS, PaaS and SaaS.
- Operational technology: ICS, IoT, SCADA.
- Endpoints and shared services: BYOD, mobile, EDR, HIDS/HIPS, email, VoIP, unified communications.
- Third-party integrations: federation, APIs, VPN, SFTP.
- Monitoring and continuity: infrastructure and content monitoring, DLP, and out-of-band communications for incident response, IT system management and business continuity or disaster recovery.
Domain 4: Identity and access management architecture
Review identity lifecycle, authentication, authorization and accounting, including the listed policy and regulatory considerations.
Identity lifecycle covers establishing and verifying identities (physical and logical), assigning identifiers to users, services, processes, devices and components, and provisioning and de-provisioning through joiners, movers and leavers processes, plus identity management technologies.
Authentication covers the approach (single-factor, multi-factor, risk-based elevation), protocols such as SAML, RADIUS, Kerberos and OAuth, control protocols such as XACML and LDAP, and trust relationships including federated and stand-alone models. Authorization covers concepts like least privilege and separation of duties, models, workflow from issuance through periodic review to revocation and suspension, privileged access management, and approaches such as SSO, rule-based, role-based and attribute-based access.
Accounting closes the loop: define audit events, establish log alerts and notifications, manage log retention and integrity, analyze and report, and comply with policies and regulations, with PCI-DSS, FISMA, HIPAA and GDPR named as examples in the outline.
For an identity and access management (IAM) scenario, practise identifying who provisions, approves, reviews and revokes access. Treat these as study questions to answer from the scenario’s requirements.
Before booking and if you need a retake
Review ISC2’s current registration policies and your appointment instructions before booking.
If you need an accommodation, contact ISC2 and submit the requested documentation before registering through Pearson. Check regional pricing and identification requirements when booking.
On retakes, two independent rules apply. After your first attempt you wait 30 test-free days; after your second, 60 days; after your third and any subsequent attempt, 90 days. Separately, you may attempt the exam at most four times within a 12-month period for the certification program.
Sources: ISSAP official English exam outline — Information Systems Security Architecture Professional Certification Exam Outline, effective August 1, 2025; How to Get Ready, Prepare for Your ISC2 Certification Exam — ISC2 before-your-exam page; What To Do After Your ISC2 Certification Exam — ISC2 after-your-exam page
After passing: endorsement and maintenance
Passing the exam is one step toward certification. Complete the application, endorsement and membership requirements afterward.
You must complete the certification application within nine months of your exam date, and you can only submit it after receiving official notification that you passed. The application needs an endorser, an ISC2 certified professional in good standing who attests to your experience, identified by member ID and surname. If you do not know one, ISC2 can endorse you, which requires proof of employment.
After approval, you commit to the ISC2 Code of Ethics and pay your first Annual Maintenance Fee before certification is granted. A percentage of applications are randomly audited, so keep your experience documentation accessible.
Maintain the credential through continuing professional education (CPE) and the annual maintenance fee, currently USD 135 for certified members. Confirm the applicable credit total with ISC2: the current policy table and footnote differ in their presentation of advanced credentials. Do not assume a total from another certification.
Sources: Endorsement | Online Endorsement Application | ISC2 — ISC2 endorsement page; What To Do After Your ISC2 Certification Exam — ISC2 after-your-exam page; Member Policies — Sections 4.1-4.2, CPE and AMF requirements
Build a study plan around your coverage gaps
Compare your resources with each current objective, retain useful explanations and fill the gaps.
Mark the objectives you can already explain and those needing study. An older resource can still contain useful material, but its table of contents or publication date alone cannot establish current coverage.
ISC2 links official self-paced training, flash cards and supplementary references. Use the detailed outline to decide where a resource helps. A polished answer or a candidate’s pass report does not establish factual accuracy.
For each design exercise, write the requirement, your proposed decision and why an alternative fails under the supplied facts. Then use timed mixed practice to revisit weaker objectives.
- Check coverage across all four domains.
- Solve the complete design exercise before revealing the answer.
- Record uncertain answers by objective and revisit their supporting references.
Sources: ISSAP official English exam outline — Information Systems Security Architecture Professional Certification Exam Outline, effective August 1, 2025; ISSAP Study Tools and Resources — ISC2 self-study resources page; ISSAP Certification Exam Outline Summary — ISC2 certification outline page
Sources
Facts checked against official sources:
