Skip to main content
Course

Security Architecture Foundations

Design security in from the blueprint, and defend every tradeoff.

Intermediate

Level

4

Modules

8

Lessons

4

Graded quizzes

2

Assignments

9 hours

Estimated time

What you will be able to do

  • Explain what a security architect does and how architecture differs from day-to-day security engineering.
  • Apply core security principles such as least privilege, defense in depth, secure defaults, and separation of duties to real design choices.
  • Turn business drivers and risk into clear security requirements, including the non-functional requirements that shape a design.
  • Reuse reference architectures and proven security patterns so you design from a known-good starting point instead of a blank page.
  • Design trust zones, segmentation, and secure data flows that contain an attacker who gains an early foothold.
  • Design a zero trust architecture using the model in National Institute of Standards and Technology (NIST) Special Publication 800-207, including policy decision and enforcement points.
  • Use Sherwood Applied Business Security Architecture (SABSA) to trace every control back to a business need.
  • Fit security into an enterprise architecture with the security views of The Open Group Architecture Framework (TOGAF), and defend your design tradeoffs to stakeholders.

What is inside

4 modules, 8 lessons. Each module ends in a graded quiz and most carry an assignment.

  1. 01

    Principles and Requirements

    Good security architecture starts with clear thinking, not a product catalog. This module defines what a security architect actually does, then grounds you in the timeless principles that guide every design, from least privilege to secure defaults and defense in depth. You will also learn to turn business drivers and risk into concrete security requirements, including the non-functional requirements that quietly make or break an architecture.

    2 lessons · 5 quiz questions

  2. 02

    Reference Architectures and Security Patterns

    Architects rarely start from a blank page, and neither should you. This module shows how to read and adapt reference architectures, building blocks, and proven security patterns so common problems get known-good answers. You will then apply that thinking to trust zones, segmentation, and secure data flows that limit how far an attacker can move after an early foothold.

    2 lessons · 5 quiz questions · assignment

  3. 03

    Zero Trust Architecture

    When the network perimeter can no longer be trusted, the architecture itself has to change. This module builds zero trust from its core idea, never trust and always verify, up through the model set out in National Institute of Standards and Technology (NIST) Special Publication 800-207. You will design the moving parts of a working zero trust architecture: the policy engine and enforcement points, identity-centric access, and microsegmentation.

    2 lessons · 5 quiz questions

  4. 04

    Enterprise Frameworks: SABSA and TOGAF

    This final module scales your work up to the whole enterprise and to the people who fund it. You will use Sherwood Applied Business Security Architecture (SABSA) to trace every control back to a business need, then fit security into broader enterprise architecture through the security views of The Open Group Architecture Framework (TOGAF). By the end you can produce architecture documentation and defend your tradeoffs to the stakeholders who have to approve, fund, and run the design.

    2 lessons · 5 quiz questions · assignment