Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2

Information Systems Security Architecture Professional

ISSAP

The ISSAP certification validates your expertise in developing, designing, and analyzing security solutions across an organization. Ideal for chief security architects and analysts, it proves you can provide risk-based guidance to senior management and align security architecture with organizational goals. Earning the ISSAP demonstrates elite-level knowledge and opens doors to new career opportunities.

343 practice questions · Updated 2026-07-30

4Domains
11Objectives
91Concepts
343Questions

ISSAP Curriculum

Every domain, objective, and concept the ISSAP exam measures.

  1. Asset Identification
  2. Business Objective Alignment
  3. Stakeholder Analysis
  4. Monitoring Design
  5. Vulnerability Management Reporting
  6. Compliance Audit Reporting
  7. Regulatory Requirements
  8. Forensic Requirements
  9. Segregation of Duties
  10. High Assurance Systems
  11. Risk Assessment Artifacts
  12. Risk Treatment Options

  1. Scope of Security Architecture
  2. Types of Security Architecture
  3. TOGAF Framework
  4. SABSA Framework
  5. Service-Oriented Modeling Framework
  6. Reference Architectures
  7. Architecture Blueprints
  8. STRIDE Threat Modeling
  9. CVSS for Vulnerability Assessment
  10. Threat Intelligence Integration
  1. Threat Modeling Results Analysis
  2. Gap Identification in Security Design
  3. Evaluation of Alternative Mitigations
  4. Internal and External Third-Party Validation
  5. Code Review Methodologies

  1. Deployment models
  2. IT and OT security
  3. Physical security controls
  4. Infrastructure and system monitoring
  5. Infrastructure and system cryptography
  6. Application security requirements
  1. Physical Security Controls
  2. Platform Security
  3. Network Security Fundamentals
  4. Storage Security
  5. Data Repository Security
  6. Cloud Security
  7. Operational Technology Security
  8. Endpoint Security
  9. Secure Shared Services
  10. Third-Party Integrations
  11. Infrastructure Monitoring
  12. Content Monitoring and DLP
  13. Out-of-Band Communications
  14. Security Controls for System Components
  1. Cryptographic design considerations
  2. Cryptographic implementation states
  3. Key management lifecycle planning

4.1 Architect identity lifecycle

4 concepts · 24 questions
  1. Identity Establishment and Verification
  2. Identifier Assignment
  3. Identity Provisioning and De-provisioning
  4. Identity Management Technologies

4.2 Architect identity authentication

13 concepts · 46 questions
  1. Authentication approach definition
  2. Single-factor authentication
  3. Multi-factor authentication
  4. Risk-based elevation
  5. SAML
  6. RADIUS
  7. Kerberos
  8. OAuth
  9. XACML
  10. LDAP
  11. Trust relationships definition
  12. Federated trust
  13. Stand-alone trust

4.3 Architect identity authorization

6 concepts · 23 questions
  1. Authorization concepts and principles
  2. Authorization models
  3. Authorization process and workflow
  4. Roles, rights, and responsibilities
  5. Privileged account management
  6. Authorization approaches

4.4 Architect identity accounting

6 concepts · 25 questions
  1. Accounting Requirements Determination
  2. Audit Event Definition
  3. Audit Log Alerting and Notification
  4. Log Retention and Integrity
  5. Log Analysis and Reporting
  6. Regulatory and Policy Compliance
Ready to practice?Test your knowledge with exam-style questions or take an intelligent quiz tailored to your level.

Percentages reflect share of the current practice bank, not official exam weightings — no structured per-skill weight is published for ISSAP, so none is invented.