Domain 3 of 4 · Chapter 1 of 3

Identify Infrastructure and System Security Requirements

Unlock the complete study guide + 1,500 practice questions across 12 full exams.

Bundled into the existing Information Systems Security Architecture Professional premium course — no separate purchase.

14-day money-back guarantee — no questions asked.

Included in this chapter:

  • What this objective produces
  • Deployment model: who holds each control
  • Operational technology: safety, timing, and conduits
  • Physical zones and accountable entry
  • Fire, utilities, and site hazards
  • Monitoring: strategy before telemetry
  • Cryptographic requirements: service, boundary, keys
  • Application security: criteria that can be evidenced
  • Security architecture documentation
  • Secure development and acquired components
  • Exam-pattern recognition

What decides each of the six requirement families

Requirement familyWhat decides the requirementWhat the requirement must stateWhere it commonly goes wrong
Deployment modelWorkload constraints: availability, latency, data sovereignty, connectivity, assurance, recoveryWhich party implements, operates, assesses, and evidences each control, and what the organization retainsChoosing for elasticity first, then discovering a mandatory constraint cannot be met
Information technology and operational technologySafety, reliability, and process-availability tolerances of the physical processThe timing and failure behavior any inline control must respect, and the permitted IT-to-OT conduitsApplying a confidentiality-first IT control set, or scanning fragile equipment to find it
Physical securityAsset criticality per zone, plus the site's environmental, utility, and occupancy hazardsWho may enter each zone, how entry and exit are recorded, and how fire, power, and cooling are providedStrengthening the perimeter while the interior remains one undivided zone
Infrastructure and system monitoringThe risk decisions the organization must keep making, and the assets that inform themWhat is monitored, how often, by whom, and how a material observation reaches a defined responseCollecting every available event with no priorities, owners, thresholds, or escalation
Infrastructure and system cryptographyData sensitivity and the security service needed during transmission and storageThe service, the protected boundary, key ownership and recovery, agility, and performance limitsMandating encryption generically and accepting provider-managed keys without asking who can read plaintext
Application securityThe system's security objectives and the acceptance decision they have to supportVerifiable criteria traced through design, implementation, and test evidence in an RTMAspirational wording such as "use strong security" that no review or test can evidence

Decision tree

Can a provider-operated environment meet every mandatory constraint? No On-premises organization implements and evidences Yes Is exclusive use of the infrastructure required? Yes Private or community cloud exclusive use, on or off premises No Must some components stay in the existing environment? Yes Hybrid controls coherent across the interconnection No Public cloud assurance, location, portability, deletion Accountability for risk and data stays with the organization on every branch the model moves only who implements, operates, assesses, and evidences each control

Cheat sheet

  • The deployment model determines control ownership and visibility
  • Hybrid designs require controls that remain coherent across boundaries
  • A private cloud is distinguished by exclusive use, not by location
  • Public cloud selection must address displaced data and services
  • Workload constraints should drive placement before technology preference
  • OT security requirements must preserve safety and reliability
  • Real-time OT behavior constrains inline security controls
  • Unsupported OT components require compensating protection
  • Passive discovery is preferred when active probing could disrupt OT
  • IT-to-OT communication must use explicit controlled conduits
  • Concentric physical zones increase protection around critical assets
  • Physical access must be authorized, monitored, and attributable
  • Fire protection must balance life safety and equipment hazards
  • Critical utilities require resilient paths without common failure points
  • Site selection must account for correlated environmental hazards
  • Monitoring frequency and scope must follow risk
  • Asset and dependency knowledge is prerequisite to monitoring coverage
  • A trusted common time source enables event correlation
  • Monitoring records must be protected from alteration and loss
  • Monitoring must produce actionable risk information
  • Data sensitivity and use cases drive cryptographic requirements
  • Cryptography complements rather than replaces access control
  • Cryptographic requirements must include algorithm agility
  • Key ownership, custody, recovery, and residency must be explicit requirements
  • Cryptographic performance and availability are design constraints
  • A Requirements Traceability Matrix links requirements to implementation and evidence
  • Security architecture documentation must record boundaries and rationale
  • Secure development practices must be integrated into the chosen SDLC
  • Third-party software requirements must cover provenance and vulnerability response
  • Application security requirements need objective acceptance criteria

Unlock with Premium — includes all practice exams and the complete study guide.

Also tested in

References

  1. ISSAP Certification Exam Outline
  2. NIST SP 800-145: The NIST Definition of Cloud Computing Whitepaper
  3. NIST SP 800-88 Rev. 1, Guidelines for Media Sanitization Whitepaper
  4. NIST SP 800-82 Rev. 3, Guide to Operational Technology (OT) Security Whitepaper
  5. NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations Whitepaper
  6. NIST SP 800-34 Rev. 1, Contingency Planning Guide for Federal Information Systems Whitepaper
  7. NIST SP 800-137, Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations Whitepaper
  8. NIST SP 800-92, Guide to Computer Security Log Management Whitepaper
  9. NIST SP 800-175B Rev. 1, Guideline for Using Cryptographic Standards in the Federal Government: Cryptographic Mechanisms Whitepaper
  10. NIST SP 800-131A Rev. 2, Transitioning the Use of Cryptographic Algorithms and Key Lengths Whitepaper
  11. NIST SP 800-57 Part 1 Rev. 5, Recommendation for Key Management: Part 1 General Whitepaper
  12. NIST Cryptographic Module Validation Program
  13. NIST SP 800-160 Vol. 1 Rev. 1: Engineering Trustworthy Secure Systems Whitepaper
  14. NIST SP 800-218, Secure Software Development Framework (SSDF) Version 1.1 Whitepaper
  15. NIST SP 800-161 Rev. 1, Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations Whitepaper