logo-img
CISSP-ISSAP training - Information Systems Security Architecture Professional

CISSP-ISSAP training - Information Systems Security Architecture Professional

4 days Classroom Engels

Sharpest price in just 2 steps

Requesting more information and/or the current price of this training is easy. We take into account any ongoing promotions, subsidies, or relationship discounts.

Description

Security professionals demonstrate with the CISSP certification that they have a solid knowledge of information security in a broad sense. However, the purpose of CISSP is not to provide equal depth in every area. CISSP certified individuals who are (going to be) involved in the design and implementation of architectural models, solutions, and technologies can deepen their knowledge with the ISSAP concentration. ISSAP examines the analytical process of information security through the lens of the most relevant domains for architecture from the CISSP CBK.

The ISSAP training is particularly suitable for security architects, security analysts, and other professionals responsible for designing and structuring information security within organizations. In this role, the security architect acts as the link between strategic decision-making at the management level and the technical implementation of security measures.

With the CISSP-ISSAP certification, you demonstrate that you possess in-depth knowledge of designing, assessing, and improving security architectures and security solutions. Additionally, the certification shows that security risks can be translated into strategic advice for management and stakeholders, ensuring that security aligns with organizational objectives and business risks.

Security Architect

The Security Architect plays a leading role in the information security of an organization. He/she is almost always (co)responsible for the development, design, and analysis of an organization-wide security plan. ISSAP certified individuals know and use best practices and standards for this task, where security architecture is primarily in service of business goals. Well-structured plans must be practically executable without too much effort while still providing sufficient protection for the organization and its (critical) information.

The role of security architect can be filled by both internal and external professionals. This makes ISSAP also very suitable for consultants who want to broaden their field or demonstrate knowledge with certification. In our training, you will be guided through the six ISSAP domains with various examples and tips. Additionally, the training is an ideal preparation for the (ISC)2 exam. To participate in the ISSAP exam, you must hold a valid CISSP certification.

AI

The CISSP-ISSAP training also covers how AI is integrated within modern security architectures and enterprise environments. The updated exam material focuses on designing secure AI-native infrastructures where AI serves both as a defense mechanism and a security risk. Topics such as AI-driven identity & access management, Zero Trust, adaptive authentication, and automated access control are explicitly part of the architectural approach. Furthermore, the training addresses AI-supported SOC, SIEM, and SOAR solutions, including securing machine learning models against attacks such as prompt injection and model manipulation. Secure AI infrastructures are also discussed, including hardware-rooted trust, trusted execution environments, micro-segmentation, and AI-driven network security. Additionally, the ISSAP covers how organizations can integrate AI risks, compliance requirements, explainability of AI decisions, and vendor risks within governance and security architectures.

Methodology

The CISSP-ISSAP training is classroom-based but can also be attended Live Online if desired. You will attend the training live remotely with our own instructor, follow along with the slides and notes on the whiteboard, and can ask questions to both the trainer and your fellow participants. So, it's basically just like being present at the classroom training, but from your own location. If the Live Online training does not meet your expectations, you may attend the classroom training again with us free of charge within a year.

Certification

This training prepares you for the CISSP-ISSAP exam from ISC2 (not included). This exam can be taken at a select number of exam locations in the Netherlands. To participate in the ISSAP exam, you must have a valid CISSP certification.

Training Requirements

  • Security Architecten
  • IT-Architecten
  • Technical Security Architecten
  • Security Consultants
  • Security Officers
  • Security Managers
  • IT Consultants
  • Auditors
  • Van de deelnemers wordt minimaal HBO- werk- en denkniveau verwacht.

Training Content

Toepasselijke normen en richtlijnen voor informatiebeveiliging

Verplichtingen rondom derden en contracten (zoals supply chain, outsourcing en partners)

Toepasselijke normen, richtlijnen en privacywetgeving rondom gevoelige en persoonsgegevens

Ontwerpen van resiliente en weerbare beveiligingsoplossingen

Identificeren van kritieke assets, organisatiedoelstellingen en stakeholders

Ontwerpen van monitoring- en rapportageprocessen (zoals vulnerability management en compliance-audits)

Ontwerpen van auditbare systemen en omgevingen (zoals wet- en regelgeving, forensische eisen, functiescheiding en high assurance-systemen)

Integreren van resultaten en documentatie uit risicoanalyses binnen securityarchitecturen

Adviseren over risicobehandeling (zoals mitigeren, overdragen, accepteren of vermijden van risico’s)

Scope van architecturen (zoals enterprise en cloud) en verschillende architectuurtypen (zoals netwerk- en service-oriented architecture (SOA))

Toepassing van architectuurframeworks (zoals The Open Group Architecture Framework (TOGAF), Sherwood Applied Business Security Architecture (SABSA) en service-oriented modeling framework)

Gebruik van referentiearchitecturen en architectuurblueprints

Toepassen van threat modeling frameworks (zoals STRIDE, Common Vulnerability Scoring System (CVSS) en threat intelligence)

Interpreteren van resultaten uit threat modeling (zoals dreigingsvectoren, impact en waarschijnlijkheid)

Identificeren van architecturale en beveiligingsgaten (gaps)

Bepalen van alternatieve oplossingen, mitigaties en compenserende maatregelen

Inzetten van interne en externe validatiemethoden (zoals tabletop exercises, modellering en simulatie, handmatige functionele reviews en peer reviews)

Toepassen van code review-methodieken (zoals dynamische, statische en handmatige analyse en source composition analysis)

Implementatiemodellen (zoals on-premises, cloud-based en hybride omgevingen)

Integratie van IT (Information Technology) en OT (Operational Technology) binnen securityarchitecturen

Fysieke beveiliging, waaronder perimeterbeveiliging, interne zonering en brandpreventie

Monitoring van infrastructuur en systemen

Toepassing van cryptografie binnen infrastructuur- en systeembeveiliging

Beveiliging van applicaties, inclusief requirements traceability, securityarchitectuurdocumentatie en secure coding

Fysieke beveiligingsmaatregelen zoals camera’s, toegangsdeuren en controlesystemen

Platformbeveiliging over fysieke, virtuele, container-, firmware- en besturingssysteemlagen

Netwerkbeveiliging over bekabelde en draadloze netwerken, IoT, firewalls, VPN, IPsec, NAC, DNS, NTP, VoIP, WAF en software-defined perimeter

Beveiliging van storage-omgevingen zoals SAN, NAS, archiefmedia en encryptie

Beveiliging van datastores met toegangsbeheer, encryptie, redactie en masking

Cloudbeveiliging binnen IaaS-, PaaS- en SaaS-omgevingen

Beveiliging van OT-omgevingen zoals ICS, IoT en SCADA-systemen

Endpointbeveiliging inclusief BYOD, mobiele devices, EDR en host-based intrusion detection/prevention

Beveiliging van gedeelde services zoals e-mail, VoIP en unified communications

Integratie van derde partijen via API’s, federatie, VPN en veilige bestandsuitwisseling (SFTP)

Monitoring van infrastructuur en technische omgevingen

Content monitoring zoals e-mail, webverkeer, data, social media en data loss prevention (DLP)

Inrichten van out-of-band communicatie voor incident response, IT-beheer en continuïteits- en herstelscenario’s

Toepassen en beoordelen van security controls per systeemcomponent (zoals webapplicaties, proxy’s en applicatieservices)

Vaststellen van cryptografische ontwerpkeuzes en beperkingen (zoals technologie, lifecycle, rekenkracht en algoritmes)

Implementeren van cryptografie voor data in transit, in use en at rest

Inrichten van de volledige levenscyclus van sleutelbeheer (generatie, opslag en distributie)

Identiteit vaststellen en verifiëren (fysiek en logisch)

Toekennen van unieke identificatoren aan gebruikers, services, processen, apparaten en componenten

Inrichten van identity provisioning en de-provisioning (zoals joiners, movers en leavers-processen)

Toepassen van identity management-technologieën

Bepalen van authenticatieaanpakken (zoals single-factor, multi-factor en risicogestuurde authenticatie)

Toepassen van authenticatieprotocollen en -technologieën zoals SAML, RADIUS, Kerberos en OAuth

Gebruik van autorisatieprotocollen en toegangscontrolemechanismen zoals XACML en LDAP

Vaststellen van vertrouwensrelaties zoals federated en stand-alone modellen

Toepassen van autorisatieprincipes zoals least privilege, separation of duties, discretionaire en verplichte toegangsmodellen

Inrichten van autorisatiemodellen op fysiek, logisch en administratief niveau

Ontwerpen en beheren van autorisatieprocessen zoals governance, uitgifte, periodieke review, intrekking en opschorting

Beheren van rollen, rechten en verantwoordelijkheden voor toegang tot systemen, applicaties en data

Inrichten van privileged access management (PAM) voor beheer van verhoogde rechten

Toepassen van toegangsmodellen zoals single sign-on, role-based, attribute-based, rule-based, token- en certificaatgebaseerde toegang

Vaststellen van vereisten voor accounting, analyse en forensisch onderzoek

Definiëren van audit-events voor logging en controle

Inrichten van log-alerts en notificaties op basis van security- en compliance-eisen

Beheren van logdata inclusief retentie, integriteit en beschikbaarheid

Uitvoeren van loganalyse en rapportage voor security- en compliance-doeleinden

Waarborgen van naleving van relevante wet- en regelgeving zoals PCI-DSS, GDPR

Description

Security professionals demonstrate with the CISSP certification that they have a solid knowledge of information security in a broad sense. However, the purpose of CISSP is not to provide equal depth in every area. CISSP certified individuals who are (going to be) involved in the design and implementation of architectural models, solutions, and technologies can deepen their knowledge with the ISSAP concentration. ISSAP examines the analytical process of information security through the lens of the most relevant domains for architecture from the CISSP CBK.

The ISSAP training is particularly suitable for security architects, security analysts, and other professionals responsible for designing and structuring information security within organizations. In this role, the security architect acts as the link between strategic decision-making at the management level and the technical implementation of security measures.

With the CISSP-ISSAP certification, you demonstrate that you possess in-depth knowledge of designing, assessing, and improving security architectures and security solutions. Additionally, the certification shows that security risks can be translated into strategic advice for management and stakeholders, ensuring that security aligns with organizational objectives and business risks.

Security Architect

The Security Architect plays a leading role in the information security of an organization. He/she is almost always (co)responsible for the development, design, and analysis of an organization-wide security plan. ISSAP certified individuals know and use best practices and standards for this task, where security architecture is primarily in service of business goals. Well-structured plans must be practically executable without too much effort while still providing sufficient protection for the organization and its (critical) information.

The role of security architect can be filled by both internal and external professionals. This makes ISSAP also very suitable for consultants who want to broaden their field or demonstrate knowledge with certification. In our training, you will be guided through the six ISSAP domains with various examples and tips. Additionally, the training is an ideal preparation for the (ISC)2 exam. To participate in the ISSAP exam, you must hold a valid CISSP certification.

AI

The CISSP-ISSAP training also covers how AI is integrated within modern security architectures and enterprise environments. The updated exam material focuses on designing secure AI-native infrastructures where AI serves both as a defense mechanism and a security risk. Topics such as AI-driven identity & access management, Zero Trust, adaptive authentication, and automated access control are explicitly part of the architectural approach. Furthermore, the training addresses AI-supported SOC, SIEM, and SOAR solutions, including securing machine learning models against attacks such as prompt injection and model manipulation. Secure AI infrastructures are also discussed, including hardware-rooted trust, trusted execution environments, micro-segmentation, and AI-driven network security. Additionally, the ISSAP covers how organizations can integrate AI risks, compliance requirements, explainability of AI decisions, and vendor risks within governance and security architectures.

Methodology

The CISSP-ISSAP training is classroom-based but can also be attended Live Online if desired. You will attend the training live remotely with our own instructor, follow along with the slides and notes on the whiteboard, and can ask questions to both the trainer and your fellow participants. So, it's basically just like being present at the classroom training, but from your own location. If the Live Online training does not meet your expectations, you may attend the classroom training again with us free of charge within a year.

Certification

This training prepares you for the CISSP-ISSAP exam from ISC2 (not included). This exam can be taken at a select number of exam locations in the Netherlands. To participate in the ISSAP exam, you must have a valid CISSP certification.

Training Requirements

  • Security Architecten
  • IT-Architecten
  • Technical Security Architecten
  • Security Consultants
  • Security Officers
  • Security Managers
  • IT Consultants
  • Auditors
  • Van de deelnemers wordt minimaal HBO- werk- en denkniveau verwacht.

Training Content

Toepasselijke normen en richtlijnen voor informatiebeveiliging

Verplichtingen rondom derden en contracten (zoals supply chain, outsourcing en partners)

Toepasselijke normen, richtlijnen en privacywetgeving rondom gevoelige en persoonsgegevens

Ontwerpen van resiliente en weerbare beveiligingsoplossingen

Identificeren van kritieke assets, organisatiedoelstellingen en stakeholders

Ontwerpen van monitoring- en rapportageprocessen (zoals vulnerability management en compliance-audits)

Ontwerpen van auditbare systemen en omgevingen (zoals wet- en regelgeving, forensische eisen, functiescheiding en high assurance-systemen)

Integreren van resultaten en documentatie uit risicoanalyses binnen securityarchitecturen

Adviseren over risicobehandeling (zoals mitigeren, overdragen, accepteren of vermijden van risico’s)

Scope van architecturen (zoals enterprise en cloud) en verschillende architectuurtypen (zoals netwerk- en service-oriented architecture (SOA))

Toepassing van architectuurframeworks (zoals The Open Group Architecture Framework (TOGAF), Sherwood Applied Business Security Architecture (SABSA) en service-oriented modeling framework)

Gebruik van referentiearchitecturen en architectuurblueprints

Toepassen van threat modeling frameworks (zoals STRIDE, Common Vulnerability Scoring System (CVSS) en threat intelligence)

Interpreteren van resultaten uit threat modeling (zoals dreigingsvectoren, impact en waarschijnlijkheid)

Identificeren van architecturale en beveiligingsgaten (gaps)

Bepalen van alternatieve oplossingen, mitigaties en compenserende maatregelen

Inzetten van interne en externe validatiemethoden (zoals tabletop exercises, modellering en simulatie, handmatige functionele reviews en peer reviews)

Toepassen van code review-methodieken (zoals dynamische, statische en handmatige analyse en source composition analysis)

Implementatiemodellen (zoals on-premises, cloud-based en hybride omgevingen)

Integratie van IT (Information Technology) en OT (Operational Technology) binnen securityarchitecturen

Fysieke beveiliging, waaronder perimeterbeveiliging, interne zonering en brandpreventie

Monitoring van infrastructuur en systemen

Toepassing van cryptografie binnen infrastructuur- en systeembeveiliging

Beveiliging van applicaties, inclusief requirements traceability, securityarchitectuurdocumentatie en secure coding

Fysieke beveiligingsmaatregelen zoals camera’s, toegangsdeuren en controlesystemen

Platformbeveiliging over fysieke, virtuele, container-, firmware- en besturingssysteemlagen

Netwerkbeveiliging over bekabelde en draadloze netwerken, IoT, firewalls, VPN, IPsec, NAC, DNS, NTP, VoIP, WAF en software-defined perimeter

Beveiliging van storage-omgevingen zoals SAN, NAS, archiefmedia en encryptie

Beveiliging van datastores met toegangsbeheer, encryptie, redactie en masking

Cloudbeveiliging binnen IaaS-, PaaS- en SaaS-omgevingen

Beveiliging van OT-omgevingen zoals ICS, IoT en SCADA-systemen

Endpointbeveiliging inclusief BYOD, mobiele devices, EDR en host-based intrusion detection/prevention

Beveiliging van gedeelde services zoals e-mail, VoIP en unified communications

Integratie van derde partijen via API’s, federatie, VPN en veilige bestandsuitwisseling (SFTP)

Monitoring van infrastructuur en technische omgevingen

Content monitoring zoals e-mail, webverkeer, data, social media en data loss prevention (DLP)

Inrichten van out-of-band communicatie voor incident response, IT-beheer en continuïteits- en herstelscenario’s

Toepassen en beoordelen van security controls per systeemcomponent (zoals webapplicaties, proxy’s en applicatieservices)

Vaststellen van cryptografische ontwerpkeuzes en beperkingen (zoals technologie, lifecycle, rekenkracht en algoritmes)

Implementeren van cryptografie voor data in transit, in use en at rest

Inrichten van de volledige levenscyclus van sleutelbeheer (generatie, opslag en distributie)

Identiteit vaststellen en verifiëren (fysiek en logisch)

Toekennen van unieke identificatoren aan gebruikers, services, processen, apparaten en componenten

Inrichten van identity provisioning en de-provisioning (zoals joiners, movers en leavers-processen)

Toepassen van identity management-technologieën

Bepalen van authenticatieaanpakken (zoals single-factor, multi-factor en risicogestuurde authenticatie)

Toepassen van authenticatieprotocollen en -technologieën zoals SAML, RADIUS, Kerberos en OAuth

Gebruik van autorisatieprotocollen en toegangscontrolemechanismen zoals XACML en LDAP

Vaststellen van vertrouwensrelaties zoals federated en stand-alone modellen

Toepassen van autorisatieprincipes zoals least privilege, separation of duties, discretionaire en verplichte toegangsmodellen

Inrichten van autorisatiemodellen op fysiek, logisch en administratief niveau

Ontwerpen en beheren van autorisatieprocessen zoals governance, uitgifte, periodieke review, intrekking en opschorting

Beheren van rollen, rechten en verantwoordelijkheden voor toegang tot systemen, applicaties en data

Inrichten van privileged access management (PAM) voor beheer van verhoogde rechten

Toepassen van toegangsmodellen zoals single sign-on, role-based, attribute-based, rule-based, token- en certificaatgebaseerde toegang

Vaststellen van vereisten voor accounting, analyse en forensisch onderzoek

Definiëren van audit-events voor logging en controle

Inrichten van log-alerts en notificaties op basis van security- en compliance-eisen

Beheren van logdata inclusief retentie, integriteit en beschikbaarheid

Uitvoeren van loganalyse en rapportage voor security- en compliance-doeleinden

Waarborgen van naleving van relevante wet- en regelgeving zoals PCI-DSS, GDPR

shape

I am taking this next step in my lifelong learning journey.

1

Applicant Information

2

Billing Information

What Can I Learn After The CISSP-ISSAP training - Information Systems Security Architecture Professional?

  • Identify and translate legal, compliance, organizational, and industry-specific security requirements into security architecture.
  • Verify and validate security designs using methods such as functional acceptance tests and regression tests.
  • Integrating cryptographic solutions within infrastructure and security architectures.
  • Designing authorization and access models based on roles, rights, and policy frameworks.
  • Integrating governance, risk management, and compliance within security architectures and security processes.
  • Analyze and incorporate infrastructure and system security requirements into architectural designs.
  • Designing and managing the complete identity lifecycle within enterprise environments.
  • Integrating logging, monitoring, and accountability within identity and access management architectures.
  • Assessing and applying different approaches to security architecture within enterprise environments.
  • Designing secure infrastructure and system architectures for complex enterprise environments.
  • Designing authentication architectures with a focus on secure and modern access mechanisms.
  • Aligning security architecture with business objectives, risks, and compliance requirements.

Schedules

This training is scheduled as follows in the coming period. Missing a date? Feel free to contact us.

Date: 18 - 21 januari 2027

Location: TSTC Veenendaal - Klassikaal & Live Online

Date: In overleg

Location:

1

Applicant Information

2

Billing Information

Learning paths

This training can also be taken as part of the below learning path(s). If you want to follow multiple titles from a learning path, please contact our advisors for a suitable bundle offer.

I am taking this next step in my lifelong learning journey.

1

Applicant Information

2

Billing Information

Why experienced professionals choose TSTC for their studies

Train smarter, not harder. TSTC's unique approach guarantees the effective acquisition of skills and the greatest chance of success.

Learn more about TSTC
Toucan Rhino