Information Systems Security Architecture Professional (CISSP-ISSAP)
Credential: Information Systems Security Architecture Professional (CISSP-ISSAP)
Credentialing Agency: International Information Systems Security Certification Consortium, Inc. (ISC)²
Renewal Period: 3 years
International Information Systems Security Certification Consortium, Inc. (ISC 2), Information Systems Security Architecture Professional (CISSP-ISSAP) is an advanced skill level information security certification. The architect plays a key role within the information security department with responsibilities that functionally fit between the C-suite and upper managerial level and the implementation of the security program and generally develop, design, or analyze the overall security plan. Although this role may typically be tied closely to technology this is not necessarily the case, and is fundamentally the consultative and analytical process of information security. The CISSP-ISSAP is an appropriate credential for Chief Security Architects and Analysts. Candidates must have two years experience in one or more of the six domains of the CISSP-ISSAP Common Body of Knowledge (CBK) and hold the CISSP certification.
More information can be found on the certifying agency's website.
Information Systems Security Architecture Professional (CISSP-ISSAP)
MINIMUM REQUIREMENTS
Attainability:
Eligibility Requirements (View Details)
- Credential Prerequisite: CISSP
- Experience: 2 years
- Education
- Training
- Membership
- Other
- Fee
Note: This credential may have multiple options for a Service member to meet eligibility requirements. Requirements listed here are based on the minimum degree required. To view other options, see the Eligibility tab.
Exam Requirements (View Details)
- Exam
- Written Exam
- Oral Exam
- Practical Exam
- Performance Assessment
Exam Administration (View Details)
- In-person exam
- Remote proctored on-line exam
- Third-party test vendor
RECERTIFICATION SUMMARY
Renewal Period: 3 years
AGENCY CONTACT INFORMATION
International Information Systems Security Certification Consortium, Inc. (ISC)²
311 Park Place Blvd
Suite 400
Clearwater, FL 33759
Phone: (866) 331-4722
Fax: (703) 356-7977
Email: communications@isc2.org
Credential Pre-requisite REQUIREMENTS
Candidate must hold the Certified Information Systems Security Professional (CISSP) in good standing.
Experience REQUIREMENTS
Candidate must demonstrate two years of experience in one or more of the six domains of the CISSP-ISSAP Common Body of Knowledge (CBK).
Other REQUIREMENTS
The Information Systems Security Architecture Professional (CISSP-ISSAP) credential has the following other requirements:
- Candidate must subscribe to the International Information Systems Security Certification Consortium, Inc. (ISC)2 Code of Ethics.
- Individuals who pass a CISSP-ISSAP exam must have their qualifications endorsed by another (ISC2) credential holder.
Written Exam
-
Identity and Access Management Architecture (19%)
- Design Identity Management and Lifecycle
- Design Access Control Management and Lifecycle
-
Security Operations Architecture (17%)
- Determine Security Operation Capability Requirements and Strategy
- Design Continuous Security Monitoring (e.g., SIEM, insider threat, enterprise log management, cyber crime, advanced persistent threat)
- Design Continuity, Availability, and Recovery Solutions
- Define Security Operations (e.g., interoperability, scalability, availability, supportability)
- Integrate Physical Security Controls
- Design Incident Management Capabilities
- Secure Communications and Networks
-
Infrastructure Security (19%)
- Determine Infrastructure Security Capability Requirements and Strategy
- Design Layer 2/3 Architecture (e.g., access control segmentation, out-of-band management, OSI layers)
- Secure Common Services (e.g., wireless, e-mail, VoIP, unified communications)
- Architect Detective, Deterrent, Preventative, and Control Systems
- Architect Infrastructure Monitoring
- Design Integrated Cryptographic Solutions (e.g., Public Key Infrastructure (PKI), identity system integration)
-
Architect for Governance, Compliance, and Risk Management (16%)
- Architect for Governance and Compliance
- Design Threat and Risk Management Capabilities
- Architect Security Solutions for Off-Site Data Use and Storage
- Operating Environment (e.g., virtualization, cloud computing)
-
Security Architecture Modeling (14%)
- Identify Security Architecture Approach (e.g., reference architectures, build guides, blueprints, patterns)
- Verify and Validate Design (e.g., POT, FAT, regression)
-
Architect for Application Security (15%)
- Review Software Development Life Cycle (SDLC) Integration of Application Security Architecture (e.g., requirements traceability matrix, security architecture documentation, secure coding)
- Review Application Security (e.g., custom, commercial off-the-shelf (COTS), in-house cloud)
- Determine Application Security Capability Requirements and Strategy (e.g., open source, cloud service providers, SaaS/IaaS providers)
- Design Application Cryptographic Solutions (e.g., cryptographic API selection, PRNG selection, software-based key management)
- Evaluate Application Controls Against Existing Threats and Vulnerabilities
- Determine and Establish Application Security Approaches for all System Components (mobile, web, and thick client applications; proxy, application, and database services)
Exam Preparation Resources
There are a number of resources available to help you prepare for the Information Systems Security Architecture Professional (CISSP-ISSAP) examination:
- Best Sources
- General References
- Related Courses
An additional resource is O'Reilly Learning Safari Books Online, a searchable digital library that provides online access to thousands of books, training videos and conference sessions. See the Educational Resources section on the Related Sites page here on COOL to learn how to get free access.
Testing Information
-
Exam Administration
Credential exams may be administered in-person at a testing site, proctored on-line remotely, or have options for both. If an exam is administered through a test vendor, the third-party test vendor box will be checked. The following test administration options apply to the Information Systems Security Architecture Professional (CISSP-ISSAP) credential where checked:
- In-person exam
- Remote proctored on-line exam
- Third-party test vendor
For more information on the International Information Systems Security Certification Consortium, Inc. (ISC)² testing process, visit the agency website.
-
Third-Party Test Vendor Information
Testing for this credential is handled by the following vendor:
Pearson VUE
The test centers are located in the U.S. They also have some test centers on military bases.
To find out more, use the following links on the Pearson VUE website:
- Search for Testing Program
- Learn About Testing for Military Communities
- Agency/Certification Specific Testing Information
- Contact Pearson VUE
RECERTIFICATION
Information Systems Security Architecture Professional (CISSP-ISSAP)
Renewal Period: 3 years