Chapter 3 of 813% of exam

Security Architecture and Engineering

Domain 3 is about building security in: design principles, formal security models, the security of different system types including cloud, cryptography and its attacks, and physical site design. Expect to pick the principle, model or algorithm that fits a scenario.

Secure design principles

The outline lists principles such as least privilege, defense in depth, secure defaults, fail securely, separation of duties, keep it simple, zero trust, privacy by design and shared responsibility. Zero trust in particular removes the assumption that anything inside the network perimeter is trustworthy.

Least privilege
Grant each entity only the minimum resources and authorizations it needs to do its work.
RFC 4949
Fail in a known state
Components fail to a defined safe state so failures do not cause loss of confidentiality, integrity or availability.
NIST SP 800-53 Rev. 5 SC-24
No implicit trust
Zero trust grants no implicit trust to assets or accounts based solely on physical or network location.
NIST SP 800-207 §2
PE, PA, PEP
The policy engine decides and logs, the policy administrator executes the decision, and the policy enforcement point enables, monitors and terminates connections.
NIST SP 800-207 §3

Security models

Formal models describe what a secure state is. Bell-LaPadula protects confidentiality, Biba protects integrity as its dual, Clark-Wilson targets commercial integrity, and Brewer-Nash prevents conflicts of interest.

Simple security property
Read access only if the subject's clearance dominates the object's classification (no read up).
RFC 4949
*-property
Write access only if the object's classification dominates the subject's clearance (no write down).
RFC 4949
Biba
Integrity levels; a subject may not modify an object at a higher or incomparable integrity level.
RFC 4949
Brewer-Nash
Enforces the Chinese wall: after reading one firm's data, a subject cannot read a competitor's in the same conflict class.
RFC 4949

Cloud and other system types

The outline asks you to assess vulnerabilities across client, server, database, cryptographic, ICS, cloud, IoT, container, serverless, embedded and virtualized systems. In cloud, the service model determines which layers the customer still controls and must secure.

IaaS
The consumer controls operating systems, storage and deployed applications but not the underlying infrastructure.
NIST SP 800-145
SaaS
The consumer controls at most limited user-specific application settings.
NIST SP 800-145
Essential characteristics
On-demand self-service, broad network access, resource pooling, rapid elasticity and measured service.
NIST SP 800-145

Cryptography

Symmetric ciphers protect bulk data efficiently, asymmetric algorithms handle key transport and signatures, and hashes check integrity. Key management, including limiting how long a key is used, often matters more than algorithm choice. Post-quantum standards now exist because large quantum computers would break today's public-key schemes.

AES
128-bit blocks with 128-, 192- or 256-bit keys.
FIPS 197
Cryptoperiod
The time span during which a specific key is authorized for use.
NIST SP 800-57 Part 1 Rev. 5 §5.3
Revocation
Certificates can become invalid before expiry, for example on key compromise; the CA revokes them and publishes status such as CRLs.
RFC 5280
Salting
A per-password random salt makes offline dictionary attacks harder because precomputed values cannot be reused.
RFC 4949
Post-quantum
FIPS 203 (ML-KEM) addresses the risk that large quantum computers could break factoring- and discrete-log-based public-key schemes, including elliptic curve.
FIPS 203 §1.2

Keep going: the full CISSP — Certified Information Systems Security Professional guide covers every section of the exam. CISSP Study Guide — 2026 Edition — PDF + EPUB, $24.99 · 14-day refund →

Studying in order?

Practice stays free. The full CISSP — Certified Information Systems Security Professional study guide is the material itself, taught start to finish — a downloadable PDF + EPUB you keep.

Get the book — $24.99
Report