Security Architecture: A Strategic Approach by InfoSec
4h 56mIntermediate2025-06-11
Authors

Infosec Institute
Course details
In this course, learn to solve security problems by understanding the impact on the business and using a risk-driven approach to prioritize and mitigate security risks. Discover the necessary skills to develop business- and risk-driven security architectures. Understand the role that you, a security architect, must play in an organization.
Skills covered
Vulnerability ManagementCybersecurityOne-Off
Concepts
Introduction
- Introduction to security architecture
- The problem - A tactical approach to study
- What is security architecture
- The role of the security architect in an enterprise
- Security design principles
- Top 10 security design principles
Enterprise Architecture Frameworks
- Enterprise (security) architecture frameworks
- Overview of the TOGAF framework
- Overview of the Zachman framework
- Overview of the SABSA framework, part 1
- Overview of the SABSA framework, part 2
Security Architecture Development Process
- Introduction
- Business requirements definitions and gathering
- Data classification
- Threat modeling and risk assessment
- Security requirements definition
- Reference security architecture
- Residual risk identification
- Architectural issues and risks
Threat Modeling
- Threat modeling
- Threat modeling and security architecture
- Threat modeling methodologies
- STRIDE threat modeling methodology
- PASTA threat modeling methodology
- OCTAVE threat modeling methodology
- Trike threat modeling methodology
- Attack trees
Designing for Security
- Introduction to security design patterns
- Security design pattern example
- Introduction to reference security architectures
- Examples of reference security architectures
Case Study
- Developing a reference security architecture
- Understanding business requirements
- Data classification
- Threat modeling and information risk assessment, part 1
- Threat modeling and information risk assessment, part 2
- Defining security requirements
- Developing the reference security architecture
- Identifying residual risk
- Identifying architectural issues and risks
Conclusion
- Summary and conclusion