Domain 3 of 4 · Chapter 2 of 3

Architect Infrastructure and System Security

Unlock the complete study guide + 1,500 practice questions across 12 full exams.

Bundled into the existing Information Systems Security Architecture Professional premium course — no separate purchase.

14-day money-back guarantee — no questions asked.

Included in this chapter:

  • Allocating controls to the boundary that enforces them
  • Physical security control sets
  • Platform security across the virtualization stack
  • Network zones, perimeters, and the management plane
  • Protected paths with VPN and IPsec
  • Admission control, hidden perimeters, and zero trust
  • Supporting services: DNS and trusted time
  • Controls for web, proxy, and application components
  • Storage security by access model
  • Data repository protection and safe release
  • Cloud boundaries and customer responsibility
  • Operational technology, ICS, and IoT
  • Endpoint security and device posture
  • Secure shared services: email and voice
  • Third-party integrations and federation
  • Infrastructure and content monitoring
  • Out-of-band paths for response and recovery
  • Reading the stem: which control is being tested

Where the enforcement boundary sits in each cloud service model

Allocation questionIaaSPaaSSaaS
What the provider operatesFundamental processing, storage, and networkingServers, operating systems, and the supported runtime platformThe application and the platform beneath it
What the customer deploys or controlsGuest operating systems, applications, and some networkingApplications built on provider-supported languages, libraries, services, and toolsUse and configuration of the provider's application
Where guest hardening and patching sitCustomerProvider, for the platform layers it managesProvider
What stays with the customer in every modelIdentities, data, configuration, and useIdentities, data, configuration, and useIdentities, data, configuration, and use
Separate axis this model does not answerWho the infrastructure is provisioned forWho the infrastructure is provisioned forWho the infrastructure is provisioned for

Decision tree

Can the component on the boundary enforce the control? Is any part of it enforced by shared infrastructure? Can another component meet the same intent? Common or hybrid control Verify the inherited scope System-specific control Document the owner Compensating control Record residual risk Is the exposure temporary and bounded? Temporary isolation, monitoring, access limits Escalate: requirement not met as designed Yes No Yes No Yes No Yes No An inherited control counts only for what actually crosses the enforcing component

Cheat sheet

  • Physical defense should combine deterrence, detection, delay, and response
  • Physical access fail states must preserve life safety
  • The hypervisor is a high-value isolation boundary
  • Containers share a host kernel and are not equivalent to virtual-machine isolation
  • Firmware resilience requires protection, detection, and recovery
  • Hardware-rooted trust can anchor higher-layer assurance
  • Platform hardening removes unnecessary functionality before exposure
  • Firewalls mediate traffic between differing security postures
  • Segmentation limits reachability and lateral movement
  • A WAF applies application-aware policy to HTTP traffic
  • A VPN protects a path but does not establish endpoint trust
  • IPsec ESP is selected when payload confidentiality is required
  • NAC makes network admission conditional on identity and posture
  • Network management paths should be isolated from user traffic
  • DNSSEC protects DNS data authenticity and integrity, not confidentiality
  • Trusted time distribution underpins logs and time-sensitive controls
  • Wireless trust boundaries separate access profiles and constrain wired reachability
  • Public services belong in a controlled perimeter network
  • A software-defined perimeter hides resources until access is authorized
  • NTP distributes time, while NTS authenticates its synchronization
  • IPsec mode follows the protected path and policy selectors
  • Zero trust separates resource-access decisions from enforcement
  • The CISA ZTMM aligns five pillars through three cross-cutting capabilities
  • The storage access model shapes the security boundary
  • Storage management interfaces require isolation from data access
  • Shared storage requires isolation between workloads and tenants
  • Backup security includes restoration assurance
  • Removable media controls span authorization through sanitization
  • Repository encryption is strongest when keys are separately controlled
  • Data masking substitutes values while preserving useful structure
  • Redaction removes sensitive content from a released representation
  • Repository access should be granted at the narrowest practical scope
  • Cloud service models shift the customer-provider control boundary
  • IaaS leaves guest systems and workloads under customer control
  • PaaS places applications and data above a provider-managed platform
  • SaaS reduces platform control but retains governance of service use
  • Deployment model and service model answer different questions
  • Cloud contracts must enable assurance and secure exit
  • The cloud control plane is a critical privileged boundary
  • OT zones should reflect process function and consequence
  • Application allowlisting fits stable, predictable OT workloads
  • OT patching must account for operational validation and maintenance windows
  • IoT gateways can enforce controls that constrained devices cannot
  • EDR combines endpoint telemetry with investigation and response
  • BYOD architecture must separate enterprise data from personal control
  • Endpoint authorization should incorporate current device posture
  • SCADA provides centralized supervision of dispersed ICS assets
  • Managed mobile endpoints need lifecycle-wide enterprise enforcement
  • HIPS attempts to block attacks detected on its host
  • S/MIME protection travels with a message beyond transport hops
  • VoIP security must address signaling and media separately
  • Unified communications controls must preserve availability and quality
  • Federation replaces local credential handling with an external trust dependency
  • SFTP provides file transfer through SSH rather than FTP over TLS
  • A third-party VPN should expose only approved integration paths
  • Every third-party integration needs a revocation and offboarding path
  • Infrastructure and content monitoring answer different questions
  • DLP applies data-handling policy across repositories, endpoints, and channels
  • Encrypted-traffic inspection creates privacy and trust trade-offs
  • A SIEM centralizes and correlates events but is not the source control
  • Content monitoring must be limited to authorized purposes
  • Control-plane activity requires monitoring distinct from workload events
  • Behavioral baselines give anomaly detection operational context
  • Social-media monitoring is governed as third-party platform collection
  • Incident communications require a path independent of the affected environment
  • Out-of-band management separates recovery access from the production data plane
  • BC/DR communications must avoid common dependencies
  • Forward and reverse proxies protect different sides of a connection
  • Server-side services must treat web clients as untrusted
  • Controls must be allocated to the component that can enforce them
  • A compensating control must meet the original control intent
  • An air gap reduces network paths but does not eliminate all transfer paths

Unlock with Premium — includes all practice exams and the complete study guide.

Also tested in

References

  1. NIST SP 800-37 Rev. 2: Risk Management Framework for Information Systems and Organizations
  2. NIST SP 800-53 Rev. 5: Security and Privacy Controls for Information Systems and Organizations Whitepaper
  3. NIST SP 800-125: Guide to Security for Full Virtualization Technologies Whitepaper
  4. NIST SP 800-190: Application Container Security Guide Whitepaper
  5. NIST SP 800-193: Platform Firmware Resiliency Guidelines Whitepaper
  6. NIST SP 800-41 Rev. 1: Guidelines on Firewalls and Firewall Policy Whitepaper
  7. NIST SP 800-153: Guidelines for Securing Wireless Local Area Networks (WLANs) Whitepaper
  8. NIST SP 800-77 Rev. 1: Guide to IPsec VPNs Whitepaper
  9. NIST SP 800-207: Zero Trust Architecture Whitepaper
  10. NIST SP 800-81-2: Secure Domain Name System (DNS) Deployment Guide Whitepaper
  11. OWASP: Web Application Firewall
  12. OWASP Input Validation Cheat Sheet
  13. NIST SP 800-209: Security Guidelines for Storage Infrastructure Whitepaper
  14. NIST SP 800-88 Rev. 1: Guidelines for Media Sanitization Whitepaper
  15. NIST SP 800-57 Part 1 Rev. 5: Recommendation for Key Management, Part 1 General Whitepaper
  16. NIST SP 800-145: The NIST Definition of Cloud Computing Whitepaper
  17. NIST SP 800-82 Rev. 3: Guide to Operational Technology (OT) Security Whitepaper
  18. NIST SP 800-213: IoT Device Cybersecurity Guidance for the Federal Government Whitepaper
  19. NIST SP 800-94: Guide to Intrusion Detection and Prevention Systems (IDPS) Whitepaper
  20. NIST SP 800-124 Rev. 2: Guidelines for Managing the Security of Mobile Devices in the Enterprise Whitepaper
  21. NIST SP 800-177 Rev. 1: Trustworthy Email Whitepaper
  22. NIST SP 800-58: Security Considerations for Voice Over IP Systems Whitepaper
  23. NIST SP 800-47 Rev. 1: Managing the Security of Information Exchanges Whitepaper
  24. NIST SP 800-63-4: Digital Identity Guidelines Whitepaper
  25. NIST SP 800-34 Rev. 1: Contingency Planning Guide for Federal Information Systems Whitepaper