Architect Infrastructure and System Security
Unlock the complete study guide + 1,500 practice questions across 12 full exams.
Bundled into the existing Information Systems Security Architecture Professional premium course — no separate purchase.
14-day money-back guarantee — no questions asked.
Included in this chapter:
- Allocating controls to the boundary that enforces them
- Physical security control sets
- Platform security across the virtualization stack
- Network zones, perimeters, and the management plane
- Protected paths with VPN and IPsec
- Admission control, hidden perimeters, and zero trust
- Supporting services: DNS and trusted time
- Controls for web, proxy, and application components
- Storage security by access model
- Data repository protection and safe release
- Cloud boundaries and customer responsibility
- Operational technology, ICS, and IoT
- Endpoint security and device posture
- Secure shared services: email and voice
- Third-party integrations and federation
- Infrastructure and content monitoring
- Out-of-band paths for response and recovery
- Reading the stem: which control is being tested
Where the enforcement boundary sits in each cloud service model
| Allocation question | IaaS | PaaS | SaaS |
|---|---|---|---|
| What the provider operates | Fundamental processing, storage, and networking | Servers, operating systems, and the supported runtime platform | The application and the platform beneath it |
| What the customer deploys or controls | Guest operating systems, applications, and some networking | Applications built on provider-supported languages, libraries, services, and tools | Use and configuration of the provider's application |
| Where guest hardening and patching sit | Customer | Provider, for the platform layers it manages | Provider |
| What stays with the customer in every model | Identities, data, configuration, and use | Identities, data, configuration, and use | Identities, data, configuration, and use |
| Separate axis this model does not answer | Who the infrastructure is provisioned for | Who the infrastructure is provisioned for | Who the infrastructure is provisioned for |
Decision tree
Cheat sheet
Unlock with Premium — includes all practice exams and the complete study guide.
Also tested in
- CCSP Certified Cloud Security Professional
- CCSP Certified Cloud Security Professional
- CCSP Certified Cloud Security Professional
- CCSP Certified Cloud Security Professional
- CCSP Certified Cloud Security Professional
- CC Certified in Cybersecurity
- CISSP Certified Information Systems Security Professional
- CISSP Certified Information Systems Security Professional
- CISSP Certified Information Systems Security Professional
- CISSP Certified Information Systems Security Professional
References
- NIST SP 800-37 Rev. 2: Risk Management Framework for Information Systems and Organizations
- NIST SP 800-53 Rev. 5: Security and Privacy Controls for Information Systems and Organizations Whitepaper
- NIST SP 800-125: Guide to Security for Full Virtualization Technologies Whitepaper
- NIST SP 800-190: Application Container Security Guide Whitepaper
- NIST SP 800-193: Platform Firmware Resiliency Guidelines Whitepaper
- NIST SP 800-41 Rev. 1: Guidelines on Firewalls and Firewall Policy Whitepaper
- NIST SP 800-153: Guidelines for Securing Wireless Local Area Networks (WLANs) Whitepaper
- NIST SP 800-77 Rev. 1: Guide to IPsec VPNs Whitepaper
- NIST SP 800-207: Zero Trust Architecture Whitepaper
- NIST SP 800-81-2: Secure Domain Name System (DNS) Deployment Guide Whitepaper
- OWASP: Web Application Firewall
- OWASP Input Validation Cheat Sheet
- NIST SP 800-209: Security Guidelines for Storage Infrastructure Whitepaper
- NIST SP 800-88 Rev. 1: Guidelines for Media Sanitization Whitepaper
- NIST SP 800-57 Part 1 Rev. 5: Recommendation for Key Management, Part 1 General Whitepaper
- NIST SP 800-145: The NIST Definition of Cloud Computing Whitepaper
- NIST SP 800-82 Rev. 3: Guide to Operational Technology (OT) Security Whitepaper
- NIST SP 800-213: IoT Device Cybersecurity Guidance for the Federal Government Whitepaper
- NIST SP 800-94: Guide to Intrusion Detection and Prevention Systems (IDPS) Whitepaper
- NIST SP 800-124 Rev. 2: Guidelines for Managing the Security of Mobile Devices in the Enterprise Whitepaper
- NIST SP 800-177 Rev. 1: Trustworthy Email Whitepaper
- NIST SP 800-58: Security Considerations for Voice Over IP Systems Whitepaper
- NIST SP 800-47 Rev. 1: Managing the Security of Information Exchanges Whitepaper
- NIST SP 800-63-4: Digital Identity Guidelines Whitepaper
- NIST SP 800-34 Rev. 1: Contingency Planning Guide for Federal Information Systems Whitepaper