Q3 2026 CALL FOR ASSOCIATE-STANDARDS IS OPEN
Defensible 10 Standards Three-Tier Program
The Program Overview
The Defensible 10 Standards provide a structured path for establishing security-first cybersecurity architecture and engineering, applying focused technical guidance, and producing documented proof.
Define the domain. Apply the guidance. Prove the results.

THE DEFENSIBLE LOOP
A 6 phase engineering model that drives the Defensible 10 Standards
The Defensible Loop is ISAUnited’s engineering model for cybersecurity architecture and engineering. It was built from repeatable failure patterns observed across a decade of intrusions and data leaks, then reverse-engineered into a disciplined workflow that teams can execute in every security domain. The loop runs through 6 phases: Define, Design, Deploy, Detect, Defend, and Demonstrate, and it ends in proof. Each Defensible 10 Standard applies the same loop within its domain to ensure security work produces measurable outcomes, traceable decisions, and evidence that can be reviewed, validated, and trusted.

PUBLIC AWARENESS MESSAGE
Cybersecurity You Cannot See, Proof You Can Expect
This public awareness message explains why cybersecurity standards matter to ordinary citizens. Hospitals, schools, airports, water systems, and payment networks rely on cybersecurity every day. Defensible 10 Standards and the Defensible Loop help organizations turn security intent into measurable outcomes through discipline, validation, and evidence. Learn how engineering-grade standards support safer lives.
THE DEFENSIBLE 10 DIFFERENCE
Foundational Standards Need Engineering Proof
This ISAUnited Technical Research Center whitepaper compares widely used ISO and NIST publications against the Defensible 10 Standards using five engineering criteria: Technical Specificity, Verifiability, Artifact Output, Granularity, and Lifecycle Integration. It computes a normalized Engineering Orientation Index to make the boundary measurable, then shows why ISO and NIST remain essential baselines while D10S serves as the missing engineering layer that turns intent into requirements, technical specifications, verification and validation, and defensible evidence.

Published: Feb 2026
THE BOOK
This book introduces the Defensible 10 Standards and provides the practitioner method for applying the ten parent domains as measurable cybersecurity architecture and engineering disciplines.
Unlike compliance frameworks that rely on documentation and audits, the Defensible 10 approach emphasizes actionable, testable engineering specifications that practitioners can design, validate, and defend using verification and validation, along with retained evidence.
Each domain profile reflects real enterprise architecture and is grounded in systems engineering discipline and defensible design practices. The authoritative standards packages are maintained online so they can be updated through governance and peer review without waiting for new editions of the books.
Designed for architects, engineers, and technical leaders, this volume serves as a reference guide and an engineering companion for advancing the profession beyond checklist tools and reactive defense. It provides a foundation for cybersecurity architecture that is measurable, repeatable, and engineered for trust.
THE DEFENSIBLE 10
Edition: First Edition 2026
ISBN: 979-8-218-78040-1

About Us
The First Cybersecurity Standards Development Organization (SDO)
For more than a century, traditional engineering disciplines have relied on structured standards—from ASME to IEEE—to ensure reliability, safety, and scientific rigor.
Cybersecurity has had no such home—until now.
The Institute of Security Architecture United (ISAUnited.org) is the world’s first and only Security Standards Development Organization (SDO) dedicated exclusively to cybersecurity architecture and engineering. Our mission is to formalize cybersecurity as an engineering discipline by producing defensible, peer-reviewed standards that are actionable, measurable, and auditable.
ISAUnited develops, maintains, and publishes the Defensible 10 Standards (D10S)—the foundational Parent Standards for secure design across all major cybersecurity domains. These standards are developed, authored, and submitted by architects and engineers from across the world, representing diverse disciplines in IT, cloud, cybersecurity, and software engineering.
Each standard is created through rigorous technical authorship, peer review by the Technical Fellow Society, and alignment with global engineering norms.




