The ISSAP — Information Systems Security Architecture Professional — is an (ISC)² concentration that sits on top of the CISSP. Where CISSP proves broad security management knowledge, ISSAP proves you can design security into systems as an architect. It’s a specialist credential for people whose job is to turn requirements and risk into concrete architecture.
Prerequisites
ISSAP requires an active CISSP in good standing plus two years of cumulative paid experience in one or more of the ISSAP domains. It is not an entry-level certification — it assumes you already hold the CISSP foundation.
The six ISSAP domains
- Architect for Governance, Compliance & Risk Management — aligning architecture to legal, regulatory, and risk requirements.
- Security Architecture Modeling — reference architectures, frameworks (SABSA, TOGAF), and verification.
- Infrastructure Security Architecture — network, endpoint, and cloud/hybrid design.
- Identity & Access Management Architecture — designing authentication, federation, and authorization.
- Architect for Application Security — secure SDLC, software assurance, and DevSecOps.
- Security Operations Architecture — monitoring, detection, and resilient operations design.
ISSAP vs CISSP
Think breadth vs depth. CISSP spans eight domains at a manager’s altitude; ISSAP drills into the architecture discipline. If your role is “security architect” or you’re moving toward designing enterprise security rather than running a program, ISSAP is the natural next step and a strong differentiator on a resume.
How to prepare
The exam is scenario-heavy: you’ll be asked to choose the best architectural decision given trade-offs in cost, risk, and business need. Practicing with realistic questions trains you to weigh those trade-offs quickly and recognize the “best” design among several workable ones.