Security Architecture Foundations
Design security in from the blueprint, and defend every tradeoff.
Tuition
$349
Intermediate
Level
4
Modules
8
Lessons
4
Graded quizzes
2
Assignments
9 hours
Estimated time
What you will be able to do
- Explain what a security architect does and how architecture differs from day-to-day security engineering.
- Apply core security principles such as least privilege, defense in depth, secure defaults, and separation of duties to real design choices.
- Turn business drivers and risk into clear security requirements, including the non-functional requirements that shape a design.
- Reuse reference architectures and proven security patterns so you design from a known-good starting point instead of a blank page.
- Design trust zones, segmentation, and secure data flows that contain an attacker who gains an early foothold.
- Design a zero trust architecture using the model in National Institute of Standards and Technology (NIST) Special Publication 800-207, including policy decision and enforcement points.
- Use Sherwood Applied Business Security Architecture (SABSA) to trace every control back to a business need.
- Fit security into an enterprise architecture with the security views of The Open Group Architecture Framework (TOGAF), and defend your design tradeoffs to stakeholders.
What is inside
4 modules, 8 lessons. Each module ends in a graded quiz and most carry an assignment.
- 01
Principles and Requirements
Good security architecture starts with clear thinking, not a product catalog. This module defines what a security architect actually does, then grounds you in the timeless principles that guide every design, from least privilege to secure defaults and defense in depth. You will also learn to turn business drivers and risk into concrete security requirements, including the non-functional requirements that quietly make or break an architecture.
2 lessons · 5 quiz questions
- 02
Reference Architectures and Security Patterns
Architects rarely start from a blank page, and neither should you. This module shows how to read and adapt reference architectures, building blocks, and proven security patterns so common problems get known-good answers. You will then apply that thinking to trust zones, segmentation, and secure data flows that limit how far an attacker can move after an early foothold.
2 lessons · 5 quiz questions · assignment
- 03
Zero Trust Architecture
When the network perimeter can no longer be trusted, the architecture itself has to change. This module builds zero trust from its core idea, never trust and always verify, up through the model set out in National Institute of Standards and Technology (NIST) Special Publication 800-207. You will design the moving parts of a working zero trust architecture: the policy engine and enforcement points, identity-centric access, and microsegmentation.
2 lessons · 5 quiz questions
- 04
Enterprise Frameworks: SABSA and TOGAF
This final module scales your work up to the whole enterprise and to the people who fund it. You will use Sherwood Applied Business Security Architecture (SABSA) to trace every control back to a business need, then fit security into broader enterprise architecture through the security views of The Open Group Architecture Framework (TOGAF). By the end you can produce architecture documentation and defend your tradeoffs to the stakeholders who have to approve, fund, and run the design.
2 lessons · 5 quiz questions · assignment