StudyToCert

All certifications / CISSP / Lessons

ISC2 CISSP 2024 outline · Domain 3: Security architecture & engineering

Secure design principles: least privilege, defense in depth, secure defaults, fail securely, zero trust, privacy by design, SASE

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Secure design principles are the rules of thumb that architects apply before any code is written or product chosen. The CISSP outline lists a set of them, including threat modeling, least privilege, defense in depth, secure defaults, fail securely, segregation of duties, keep it simple, zero trust, trust but verify, privacy by design, shared responsibility and secure access service edge (SASE). The exam expects you to recognize each from a description and to pick the principle that a design follows or violates.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CISSP for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CISSP study plan