Identify Infrastructure and System Security Requirements
Unlock the complete study guide + 1,500 practice questions across 12 full exams.
Bundled into the existing Information Systems Security Architecture Professional premium course — no separate purchase.
14-day money-back guarantee — no questions asked.
Included in this chapter:
- What this objective produces
- Deployment model: who holds each control
- Operational technology: safety, timing, and conduits
- Physical zones and accountable entry
- Fire, utilities, and site hazards
- Monitoring: strategy before telemetry
- Cryptographic requirements: service, boundary, keys
- Application security: criteria that can be evidenced
- Security architecture documentation
- Secure development and acquired components
- Exam-pattern recognition
What decides each of the six requirement families
| Requirement family | What decides the requirement | What the requirement must state | Where it commonly goes wrong |
|---|---|---|---|
| Deployment model | Workload constraints: availability, latency, data sovereignty, connectivity, assurance, recovery | Which party implements, operates, assesses, and evidences each control, and what the organization retains | Choosing for elasticity first, then discovering a mandatory constraint cannot be met |
| Information technology and operational technology | Safety, reliability, and process-availability tolerances of the physical process | The timing and failure behavior any inline control must respect, and the permitted IT-to-OT conduits | Applying a confidentiality-first IT control set, or scanning fragile equipment to find it |
| Physical security | Asset criticality per zone, plus the site's environmental, utility, and occupancy hazards | Who may enter each zone, how entry and exit are recorded, and how fire, power, and cooling are provided | Strengthening the perimeter while the interior remains one undivided zone |
| Infrastructure and system monitoring | The risk decisions the organization must keep making, and the assets that inform them | What is monitored, how often, by whom, and how a material observation reaches a defined response | Collecting every available event with no priorities, owners, thresholds, or escalation |
| Infrastructure and system cryptography | Data sensitivity and the security service needed during transmission and storage | The service, the protected boundary, key ownership and recovery, agility, and performance limits | Mandating encryption generically and accepting provider-managed keys without asking who can read plaintext |
| Application security | The system's security objectives and the acceptance decision they have to support | Verifiable criteria traced through design, implementation, and test evidence in an RTM | Aspirational wording such as "use strong security" that no review or test can evidence |
Decision tree
Cheat sheet
Unlock with Premium — includes all practice exams and the complete study guide.
Also tested in
References
- ISSAP Certification Exam Outline
- NIST SP 800-145: The NIST Definition of Cloud Computing Whitepaper
- NIST SP 800-88 Rev. 1, Guidelines for Media Sanitization Whitepaper
- NIST SP 800-82 Rev. 3, Guide to Operational Technology (OT) Security Whitepaper
- NIST SP 800-53 Rev. 5, Security and Privacy Controls for Information Systems and Organizations Whitepaper
- NIST SP 800-34 Rev. 1, Contingency Planning Guide for Federal Information Systems Whitepaper
- NIST SP 800-137, Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations Whitepaper
- NIST SP 800-92, Guide to Computer Security Log Management Whitepaper
- NIST SP 800-175B Rev. 1, Guideline for Using Cryptographic Standards in the Federal Government: Cryptographic Mechanisms Whitepaper
- NIST SP 800-131A Rev. 2, Transitioning the Use of Cryptographic Algorithms and Key Lengths Whitepaper
- NIST SP 800-57 Part 1 Rev. 5, Recommendation for Key Management: Part 1 General Whitepaper
- NIST Cryptographic Module Validation Program
- NIST SP 800-160 Vol. 1 Rev. 1: Engineering Trustworthy Secure Systems Whitepaper
- NIST SP 800-218, Secure Software Development Framework (SSDF) Version 1.1 Whitepaper
- NIST SP 800-161 Rev. 1, Cybersecurity Supply Chain Risk Management Practices for Systems and Organizations Whitepaper