← CISSP: security, risk, and operations
03 / 8 · 30 MIN

Architecture, cryptography, and common failures

Design protection for normal conditions and concrete failures.

Concept and mechanism

A secure architecture makes trust boundaries and dependencies explicit. Two machines on one power circuit and switch remain vulnerable to common failures. Two sites depending on one key service can also fail together. Testing must match the loss event the requirement intends to withstand. Stopping a VM does not prove site recovery. Define failure behavior by context: an API may need to deny operations without confirmed authorization, while an emergency exit requires human-safety analysis and physical requirements. Do not generalize a fail-closed rule without considering the loss it could cause in another system.

Guided application

Cryptography provides specific properties. Encryption alone does not guarantee modification detection; choose authenticated-integrity mechanisms where needed. A shared-key MAC does not distinguish exclusive authorship between both holders. Signatures use a different key model, but evidence still depends on custody, identity, and validation. Plan key generation, protection, use, rotation, and recovery. An encrypted backup without recoverable keys may have no operational value. In cloud, identify the specific service boundary: on customer-managed EC2, guest-system patches still need an owner. For an AI service, also include models, inference data, and processing dependencies in trust boundaries. The diagram and responsibility matrix should let APS recognize what it operates and what depends on third parties.

IN PRACTICE

The secondary site has compute available but cannot decrypt data without the primary site: the key service is a resilience dependency.

Common pitfalls

Quantity treated as independence; encryption treated as universal integrity; MAC treated as exclusive authorship; cloud treated as transfer of every responsibility.

Related topics: Networks, channels, and access boundaries · Identity, sessions, and privileges

Take this idea with you

Demonstrate required properties and dependencies that must survive failure.

Create account

Reference: Engineering Trustworthy Secure Systems · CISSP outline effective April 15, 2024; current AI guidance consulted 2026-09-29