The ISSAP — Information Systems Security Architecture Professional — is an (ISC)² concentration that sits on top of the CISSP. Where CISSP proves broad security management knowledge, ISSAP proves you can design security into systems as an architect. It’s a specialist credential for people whose job is to turn requirements and risk into concrete architecture.
Prerequisites
ISSAP requires an active CISSP in good standing plus two years of cumulative paid experience in one or more of the ISSAP domains. It is not an entry-level certification — it assumes you already hold the CISSP foundation.
The four ISSAP domains
The outline effective 1 August 2025 replaced the earlier six-domain structure with four. Application security and operations did not disappear — they were folded into the infrastructure and modeling domains, which is why that domain now carries the largest share of the exam.
- Governance, Risk, and Compliance — 21% — aligning architecture to legal, regulatory, and risk requirements.
- Security Architecture Modeling — 22% — reference architectures, frameworks (SABSA, TOGAF), and verification.
- Infrastructure and System Security — 32% — network, endpoint, cloud/hybrid, cryptographic, and operational design.
- Identity and Access Management Architecture — 25% — designing authentication, federation, and authorization.
The exam is 125 items in 180 minutes, scored on a scale to 1000 with a pass mark of 700.
ISSAP vs CISSP
Think breadth vs depth. CISSP spans eight domains at a manager’s altitude; ISSAP drills into the architecture discipline. If your role is “security architect” or you’re moving toward designing enterprise security rather than running a program, ISSAP is the natural next step and a strong differentiator on a resume.
How to prepare
The exam is scenario-heavy: you’ll be asked to choose the best architectural decision given trade-offs in cost, risk, and business need. Practicing with realistic questions trains you to weigh those trade-offs quickly and recognize the “best” design among several workable ones.