top of page
Image by GuerrillaBuzz

Cybersecurity Architecture - Professional Program

Learn to design defensible enterprise and cloud architectures that hold up under real-world threats. Model trust boundaries, apply proven patterns, map to the Defensible 10, and produce evidence you can defend.

Cybersecurity Architecture — Pro Bundle

Payment options available

 

A complete path to cybersecurity architecture practice and proof. Includes full course access and the CPL capstone portfolio review. Your evaluation is based on your architecture artifacts, evidence, and outcomes.

Includes:

  • Course access

  • Course eBooks

  • CPL capstone review (1 attempt)

  • Plus, a lifetime ISAU membership

What will I Learn?

Cybersecurity Architecture Program

Description

The Cybersecurity Architecture Program is a professional training path built for practitioners who want to move beyond point solutions and learn how to design and govern secure systems at enterprise scale. This program develops the Defensible Designer - the cybersecurity architect who can shape resilient architectures, lead defensible reviews, and keep risk visible from early concept through delivery and operational change.

You will learn a disciplined, repeatable method for translating business objectives and risk into measurable security requirements, modeling systems with clear views, trust boundaries, interfaces, dependencies, and failure domains, and using structured adversarial analysis to identify threats that matter. You will strengthen your justification of design choices, document trade-offs clearly, and align protections with standards so that architectural work produces evidence that holds up to scrutiny, not just diagrams.

The program is delivered in two progressive parts, Fundamentals and Advanced, so you can apply core architecture methods immediately and then scale into governance, reusable patterns, measurable outcomes, and leadership practices. If you are a security practitioner, architect, senior engineer, or aspiring technical leader seeking a practical architectural discipline that works in real organizations, this program provides the structure to design and sustain security over time.

Field of study: Cybersecurity Architecture

 

Program level: Certified Professional

 

Pathway: Certified Professional Cybersecurity Architect (CPCA) License

 

Delivery format: 100% online (self-paced) with technical instructor support

 

Pace: 10 days (2 weeks)

 

Prerequisites:​ Cybersecurity Essentials are required for this program; see below. 

 

Credits: 20 CPEs

 

Assessment: Capstone Portfolio

 

ISAU-eBK-Expert-ARC_cover.png

Mastering Cybersecurity Architecture (ebook included)

The official course text and primary reference for cybersecurity architecture. It is used in knowledge checks and in the professional portfolio review, guiding practitioners in applying the Defensible Architecture framework to translate clear requirements into defensible architecture decisions and evidence that withstands scrutiny.

Edition:      First Edition 2026

  • Practical methods: system modeling, trust boundaries, threat analysis, decision records, risk-driven design.

  • Helps you turn business and risk goals into measurable requirements.

  • Guides repeatable design reviews that produce traceable outcomes and durable architectures.

What will I take?

BASIC Courses

B100 

Course: Defensible 10 Standards Foundations

Field: Cybersecurity Essentials

This course introduces students to the Defensible 10 Standards and explains how the ten domains organize security responsibilities across enterprise and cloud environments. Students learn the purpose of each domain, the relationships among controls, requirements, and measurable acceptance criteria, and how to interpret a system diagram through the D10S lens. 

B102

Course: Cybersecurity Core Principles
 

Field: Cybersecurity Essentials

A practical introduction to the ideas that anchor secure design, from confidentiality and integrity to least privilege, layered defenses, and verifiable operations. Learn how these principles shape choices in architecture, configuration, and daily practice across data centers and cloud services. Through real examples and guided critiques, connect each principle to measurable outcomes that reduce risk and produce resilient, trustworthy systems.

B104

Course: Cybersecurity Controls Management Framework

Field: Cybersecurity Essentials

This course teaches students how to build a clear, organized system for selecting, mapping, measuring, and maintaining security controls across enterprise and cloud environments. Students learn to translate policy goals into concrete requirements, plan evidence from the outset, and conduct ongoing checks that demonstrate that protections work in real-world operations.

B107

Course: Security by Design Foundations

Field: Cybersecurity Essentials

Security by Design Foundations teaches you to plan and review security like an engineer: set measurable goals, use simple design models to place controls, make sound trade-offs, add lightweight delivery guardrails, and produce evidence that your choices work. Built for both managers and technical teams.

 

B108

Course: Security Project Management
 

Field: Cybersecurity Essentials

This course introduces students to security project management as a disciplined practice for planning and delivering secure technology work. Students learn to define scope, roles, and milestones; manage risks and dependencies; coordinate technical and business stakeholders; and track security outcomes from requirements through validation.

CORE Courses

ENG651

Course: Defensible Engineering Mechanisms

Field: Cybersecurity Engineering

Explore how defensive mechanisms are identified, designed, and verified within secure enterprise and cloud systems. It explains how mechanisms such as gateways, firewalls, identity services, scanners, WAF, and monitoring components enforce protection across architectures. Learners study how these mechanisms are placed, tested, and sustained to ensure defensible, measurable security outcomes.

CORE Courses

ARC500

Course: Introduction to Defensible Architecture

Field: Cybersecurity Architecture

Introduces defensible cybersecurity architecture and explains how ten security domains organize responsibilities across enterprise and cloud environments. Clarifies the purpose of each domain, how controls connect to requirements and measurable acceptance criteria, and how to read a system diagram as an architectural security map that supports consistent design reviews and accountable outcomes.

ARC504

Course: Security Design Operations
 

Field: Cybersecurity Architecture

Security design operations define how security architecture is executed within technical design authorities and centers of excellence across enterprise and cloud environments. It shows how to interpret system diagrams, clarify security responsibilities across key domains, and translate design decisions into control expectations, requirements, and measurable acceptance criteria.

ARC550

Course: Defensible Architecture Design Framework

Field: Cybersecurity Architecture

This course introduces students to the Defensible 10 Standards and explains how the ten domains organize security responsibilities across enterprise and cloud environments. Students learn the purpose of each domain, the relationships among controls, requirements, and measurable acceptance criteria, and how to interpret a system diagram through the D10S lens. 

ARC551

Course: Technical Adversarial & Defensible Analysis (Advanced)

Field: Cybersecurity Architecture

This advanced course teaches how to review a solution architecture diagram from an attacker’s perspective and translate findings into a defensible security design. Students learn to map attack stages and entry points, threat-model components and data flows, align attacker behaviors to real techniques, and produce clear remediation recommendations.

ARC552

Course Title: Cybersecurity Design Models (CDM) Practicum

Field: Cybersecurity Architecture

This practicum develops practical modeling skills for designing secure system architectures using structured, repeatable techniques. Learners will apply real-world design principles to model system components, assess exposure, and document defensible architecture patterns, with a focus on modularity, precision, and traceability in design workflows.

 

ARC554

Course Title: Cloud Security Architecture Design

Field: Cybersecurity Architecture

This course examines how secure cloud systems are architected through structured design practices. It covers foundational engineering concepts, including landing zone architecture, hub-and-spoke segmentation, tenant isolation, encryption and key management, and secure workload deployment. Learners gain practical insight into aligning design principles, trust boundaries, and security controls across multi-cloud and hybrid environments.

What is the Exam?

Cyber Capstone Portfolio

Description

A focused, real-world scenario that lets you prove mastery through a concise, defensible submission. The Capstone Portfolio is a solo, written, remote, and time-boxed to two weeks (10 business days) from assignment. Earlier submission is acceptable. There are no multiple-choice tests and no interviews.

 

What you will complete

  • Artifact 1: Project Brief and Scope
    Define the problem, project scope, requirements, technical specifications, assumptions, constraints, and risk context.

  • Artifact 2: High-Level Architecture and System Context
    Present the system context, trust boundaries, major components, entry surfaces, and initial control direction.

  • Artifact 3: Detailed Deployment and Threat Analysis
    Show the deployment design and placement of defensible engineering mechanisms, supported by Technical Adversarial and Defensible Analysis.

  • Artifact 4: Detection and Response Strategy
    Provide the monitoring approach, detection logic, incident-response considerations, and operational-readiness plan.

  • Artifact 5: Defensible Design and Residual Risk Briefing
    Summarize the final defensible decisions, tradeoffs, residual risk, and supporting rationale in a concise presentation deck with speaker notes.

How it is evaluated

Your submission is evaluated using the ISAUnited Defensible Capability Score, a two-section scoring model based on written deliverables only.

Part 1 - Technical Artifact Evaluation (Pass or Fail), scores the submitted capstone artifacts across the Define, Design, Deploy, Detect, and Defend phases for technical completeness, correctness, traceability, and defensibility.

Part 2 - Skills, Knowledge, and Abilities (SKA) Capability Profile (Professional Capability) evaluates how you performed through the capstone by assessing disciplined practice, reasoning quality, judgment, and communication across seven capability dimensions, with evidence references tied to the submitted artifacts.

 

Outcome
Successful completion satisfies the Capstone requirement for the ISAUnited Certified Professional License in your selected track.

What Do I Get?

CPL_Arch_Sample_2025.PNG

Your Professional License - Certified Professional Cybersecurity Architect  (CPCA)

This is the license you earn when you pass the CPCA CPL evaluation (included in the Pro Bundle). The evaluation is capstone-based—no multiple-choice exams. A successful review adds your name to the ISAUnited public registry.

  • Designation: Certified Professional Cybersecurity Architect (CPCA)

  • Credentialing: Digital certificate + verifiable License ID/issue date

  • The Certified Professional License is valid for a three-year term.

  • Renewal requires 60 Continuing Professional Education credits

Are you Ready?

Do you have questions about which program to choose or how the CPL works? Book a quick consult and we’ll help you or send us a message below.

Scrabble Letters

Acronym Library

Decode Our Alphabet Soup!

bottom of page