Copyright (c) 2026 MindMesh Academy. All rights reserved. This content is proprietary and may not be reproduced or distributed without permission.

4. Domain 3 — Security Architecture and Engineering (13%)

Security architecture is where organizational risk decisions become technical reality. Domain 1 defined what you're protecting and why; Domain 2 defined the objects and their sensitivity; Domain 3 defines how systems are designed and built to honor those requirements. Architecture decisions made here — trust boundaries, security models, cryptographic choices — have consequences that persist for the life of the system, often decades.

At 13% of the exam, Domain 3 is the most technically dense domain. It spans formal access control models developed in the 1970s (still tested), modern cryptographic algorithms, and the physical security of the facilities housing it all. The common thread is design — every concept here is about building security in, not bolting it on.

⚠️ Domain Trap: Domain 3 contains the most memorization-heavy material in the CISSP — but the exam tests application, not recall. Knowing Bell-LaPadula's rules is insufficient; you must be able to identify which model applies to a given scenario and why. Knowing AES uses 128/192/256-bit keys isn't enough — you must recognize when AES is wrong for a use case and what to use instead.

Alvin Varughese
Written byAlvin Varughese
Founder15 professional certifications