StudyToCert

All certifications / CISSP / Lessons

ISC2 CISSP 2024 outline · Domain 3: Security architecture & engineering

Controls based on system security requirements; evaluation criteria (Common Criteria)

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Choosing controls should start with requirements, not products. A system's security requirements come from its data classification, business function, laws and contracts, risk assessment and the organization's policies. Once you know what the system must achieve, for example 'only authenticated clinicians can view patient records, and every access is logged', you select controls that meet those requirements and later verify that they do. Starting from a favorite product instead often leaves real requirements unmet while spending money on features nobody needed.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CISSP for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CISSP study plan