ISC2 Information Systems Security Architecture Professional (ISSAP) focuses on the design and analysis of security architectures that support organizational objectives, risk requirements, and complex technical environments. It is intended for experienced professionals who translate business and security requirements into defensible architectural decisions, as well as organizations developing senior staff responsible for enterprise security design.
The curriculum covers governance, risk, and compliance; security architecture modeling; infrastructure and system security architecture; and Identity and Access Management (IAM) architecture. Participants examine architectural frameworks, reference models, threat modeling, design validation, platform and network security, cloud and operational technology, cryptographic solutions, identity lifecycle management, authentication, authorization, privileged access, and audit architecture. These areas are addressed as connected elements of an enterprise security architecture rather than as isolated controls.
ISSAP training is directed toward security architects, systems architects, network designers, senior consultants, and other professionals who advise leadership and shape security across complex environments. Candidates may qualify through an active CISSP and two years of relevant experience or through seven years of cumulative experience across the ISSAP domains. Organizations can use the training to strengthen architecture governance, improve consistency across security designs, and develop professionals capable of aligning technical solutions with business strategy, risk tolerance, and regulatory obligations.