Security Architecture & Engineering
Reference architectures, control frameworks (NIST SP 800-53, CIS Controls), secure-by-design patterns, threat modeling, trust-boundary design, technology standards.
Build, Connect & Operate
Build and run the systems — apps, cloud, data, networks, OT, AI infra, supply chain, quantum engineering.
Other domains in this layer
Curated resources
Authoritative sources we ground Security Architecture & Engineering questions in — frameworks, research, guides, and tools.
NIST SP 800-160 Vol. 1 Rev. 1 — Engineering Trustworthy Secure Systems
The systems-security-engineering doctrine: lifecycle processes, design principles, and assurance for trustworthy systems. The most rigorous federal reference for security architecture.
SABSA — Sherwood Applied Business Security Architecture
Business-driven security architecture framework. Six-layer model (contextual → operational) widely used in enterprise security architecture programs. Vendor-neutral; common in EA practice.
Threat Modeling Manifesto
Authored by Adam Shostack and other practitioners. Defines values, principles, and patterns for effective threat modeling. The reference for "what is good threat modeling."
Cloud Security Alliance — Cloud Controls Matrix (CCM)
Cloud-specific control framework with 197 controls across 17 domains. Mapped to NIST 800-53, ISO 27001, PCI DSS, GDPR. The reference for cloud-architecture control questions.
NCSC Cyber Security Design Principles
Five top-level principles (establish context, make compromise difficult, make disruption difficult, make compromise detection easier, reduce the impact of compromise) with sub-principles. Concise, vendor-neutral, widely cited in architecture practice.
Certifications that signal this domain
Credentials whose blueprint meaningfully covers this domain. Core means centrally covered; also touched means present in the blueprint but not the primary focus.
Core coverage
Apple Certified Support Professional
Apple Certified Support Professional
Amazon Web Services Certified Security - Specialty
The AWS Security Specialty is AWS's most demanding security certification and requires solid practical experience with AWS workloads. It covers a broad spectrum: from IAM and data encryption to incident response, logging, and compliance. The practical relevance is high; pure textbook candidates typically fail. The certification has high market value potential, as it is regarded as proof of quality for security architects in cloud environments. Important: Version SCS-C02 was superseded in December 2025; SCS-C03 is now current.
Amazon Web Services Certified Solutions Architect - Associate
Amazon Web Services Certified Solutions Architect - Associate
Amazon Web Services Certified Solutions Architect - Professional
Amazon Web Services Certified Solutions Architect - Professional
Microsoft Azure Solutions Architect Expert
Microsoft Azure Solutions Architect Expert
CompTIA Advanced Security Practitioner+
CompTIA's SecurityX (formerly CASP+, current exam code CAS-005) is one of the few vendor-neutral advanced certifications for technical security experts without management focus. It deliberately positions itself as a technical alternative to CISSP and is recognized by DoD and US government agencies as an 8570-compliant credential, which is a real advantage in government environments. In the private sector, market perception is mixed: CISSP clearly dominates job postings, but SecurityX provides a credible signal for technically deep skills. The pass/fail format without score disclosure is unusual and criticized by some as lacking transparency. Performance-based questions increase the practical rigor.
Cisco Certified Internetwork Expert - Enterprise Infrastructure
Cisco Certified Internetwork Expert - Enterprise Infrastructure
Cisco Certified Implementation Expert - Security
Cisco Certified Implementation Expert - Security
Checkpoint Certified Security Expert
Checkpoint Certified Security Expert
Certified Cloud Security Professional
Cloud security architecture: shared responsibility, identity, data protection, crypto, and cloud-native detection.
CertNexus Certified Internet of Things Security Practitioner
CertNexus Certified Internet of Things Security Practitioner
IBITGQ Certified ISO 27001 Information Security Management Specialist Lead Implementer
IBITGQ Certified ISO 27001 Information Security Management Specialist Lead Implementer
Certified Information Systems Security Professional
Breadth across security engineering, architecture, operations, and governance at senior-IC / manager level. The default senior-generalist signal.
CISSP Information Systems Security Architecture Professional
Architecture concentration on top of CISSP — trust boundaries, identity / crypto / network composition, defense-in-depth design.
EC Council Certified Network Defense Architect
EC Council Certified Network Defense Architect
CREST Certified Network Intrusion Analyst
CREST Certified Network Intrusion Analyst
CREST Registered Technical Security Architect
CREST Registered Technical Security Architect
CREST Certified Simulated Attack Manager
CREST Certified Simulated Attack Manager
Certified Secure Software Lifecycle Professional
Secure SDLC, threat modelling, secure architecture across product teams.
CWNP Certified Wireless Security Professional
CWNP Certified Wireless Security Professional
eLearnSecurity Network Defense Professional
eLearnSecurity Network Defense Professional
F5 Big-IP Certified Technical Specialist - Domain Name Services
F5 Big-IP Certified Technical Specialist - Domain Name Services
GIAC Critical Controls Certification
GIAC Critical Controls Certification
GIAC Defensible Security Architecture
GIAC Defensible Security Architecture
ISA Certified Design Specialist
ISA Certified Design Specialist
ISA Certified Fundamentals Specialist
ISA Certified Fundamentals Specialist
ISA Certified Risk Assesment Specialist
ISA Certified Risk Assessment Specialist
Information Systems Security Architecture Professional
ISC2 specialization for security architecture. Requires an active CISSP. Focus on GRC, Security Architecture Modeling, Infrastructure Security, and IAM architecture. For senior security architects in enterprise environments.
Information Systems Security Engineering Professional
ISC2 specialization for security engineering, developed in cooperation with NSA. Focus on Systems Security Engineering, Risk Management, and Security Planning. Particularly relevant in US Government/Defense context.
Certiport IT Specialist - Network Security
Certiport IT Specialist - Network Security
Juniper Networks Certified Internet Expert, Security
Juniper Networks Certified Internet Expert, Security
Juniper Networks Certified Internet Professional, Security
Juniper Networks Certified Internet Professional, Security
Linux Foundation Certified IT Associate
Linux Foundation Certified IT Associate
Linux Foundation Certified System Administrator
Linux Foundation Certified System Administrator
Linux Professional Institute Certified: Linux Administrator
Linux Professional Institute Certified: Linux Administrator
Linux Professional Institute Certified: Linux Engineer
Linux Professional Institute Certified: Linux Engineer
Linux Professional Institute Certified: 303 Security
Linux Professional Institute Certified: 303 Security
ISECOM OSSTMM Wireless Security Expert
ISECOM OSSTMM Wireless Security Expert
Prisma Certified Cloud Security Engineer
Prisma Certified Cloud Security Engineer
PDSO Certified DevSecOps Professional
PDSO Certified DevSecOps Professional
SABSA Chartered Security Architect - Foundation Certificate
SABSA Chartered Security Architect - Foundation Certificate
SABSA Chartered Security Architect - Master Certificate
SABSA Chartered Security Architect - Master Certificate
SABSA Chartered Security Architect - Practitioner Certificate
The SABSA Chartered Practitioner (SCP) certification is the most internationally recognized qualification for risk-based security architecture at enterprise level. The SABSA framework pursues a consistently business-driven, attribute-based approach to security architecture, clearly distinguishing itself from technology-heavy frameworks. The market for SABSA is niche but highly specialized: the certification is known and valued particularly in large enterprises, the financial sector, and critical infrastructure. The assignment-based exam requires real practical application and cannot be passed through mere memorization – this increases the credibility of the credential. Limited adoption and lengthy training paths are the main limitations.
Microsoft Cybersecurity Architect
The Microsoft Certified: Cybersecurity Architect Expert (SC-100) is Microsoft's highest security certification and targets experienced professionals who design security architectures for hybrid and cloud-native environments based on the Microsoft platform. It requires at least one associate-level security certification (e.g., AZ-500, SC-200, or SC-300) and builds on that knowledge. The certification addresses zero-trust architectures, compliance requirements, identity governance, and infrastructure protection from a strategic perspective. For organizations heavily invested in Microsoft 365 and Azure, SC-100 is valuable proof of expertise; outside the Microsoft ecosystem, its relevance is more limited. The exam will be updated in April 2026.
Salesforce Certified Technical Architect
Salesforce Certified Technical Architect
SecOps Group Certified Network Security Practitioner
SecOps Group Certified Network Security Practitioner
SANS Security Awareness Professional
SANS Security Awareness Professional
OpenGroup TOGAF Certified
TOGAF is the world's leading standard for Enterprise Architecture and is considered a de-facto mandatory qualification for EA roles in many large enterprises. The certification provides a structured framework (ADM) for developing and maintaining enterprise architectures, but is more methodological than technically deep. Critics note that the framework appears abstract and process-heavy and is often applied only selectively in practice. Nevertheless, market acceptance is high: TOGAF knowledge is frequently explicitly required in job postings for EA roles. The certificate does not expire, making it a one-time investment without recertification effort.
VMware Certified Design Expert in Datacenter Virtualization
VMware Certified Design Expert in Datacenter Virtualization
VMware Certified Implementation Expert in Datacenter Virtualization
VMware Certified Implementation Expert in Datacenter Virtualization
VMware Certified Implementation Expert in Network Virtualization
VMware Certified Implementation Expert in Network Virtualization
VMware Certified Professional in Datacenter Virtualization
VMware Certified Professional in Datacenter Virtualization
Protocol Analysis Institute Wireshark Certified Network Analyst
Protocol Analysis Institute Wireshark Certified Network Analyst
Zachman Enterprise Architect Professional (Level 3)
Zachman Enterprise Architect Professional (Level 3)
Also touched
Certified Chief Information Security Officer
Executive leadership — governance, program mgmt, finance, and strategic planning for security.
Certified Information Security Manager
Security program management, risk, governance, and incident governance. The manager / CISO-track signal.
Browse all certifications → — pick a cert on the interactive map to highlight every domain it covers.
More in Cybersecurity
Test what you know about Security Architecture & Engineering
40 questions available. Beginner to expert questions, scored against the global leaderboard.