Security Architecture and Engineering
Domain 3 is about building security in: design principles, formal security models, the security of different system types including cloud, cryptography and its attacks, and physical site design. Expect to pick the principle, model or algorithm that fits a scenario.
Secure design principles
The outline lists principles such as least privilege, defense in depth, secure defaults, fail securely, separation of duties, keep it simple, zero trust, privacy by design and shared responsibility. Zero trust in particular removes the assumption that anything inside the network perimeter is trustworthy.
Security models
Formal models describe what a secure state is. Bell-LaPadula protects confidentiality, Biba protects integrity as its dual, Clark-Wilson targets commercial integrity, and Brewer-Nash prevents conflicts of interest.
Cloud and other system types
The outline asks you to assess vulnerabilities across client, server, database, cryptographic, ICS, cloud, IoT, container, serverless, embedded and virtualized systems. In cloud, the service model determines which layers the customer still controls and must secure.
Cryptography
Symmetric ciphers protect bulk data efficiently, asymmetric algorithms handle key transport and signatures, and hashes check integrity. Key management, including limiting how long a key is used, often matters more than algorithm choice. Post-quantum standards now exist because large quantum computers would break today's public-key schemes.
Keep going: the full CISSP — Certified Information Systems Security Professional guide covers every section of the exam. CISSP Study Guide — 2026 Edition — PDF + EPUB, $24.99 · 14-day refund →

Practice stays free. The full CISSP — Certified Information Systems Security Professional study guide is the material itself, taught start to finish — a downloadable PDF + EPUB you keep.