top of page
D10S_hero_bkgd_v1_2026.png

About Us

ISAUnited develops real-world, ANSI-recognized cybersecurity standards that turn security architecture and engineering expectations into measurable, verifiable, and evidence-backed outcomes.

hero_about_pg_image.png

Cybersecurity standards built for architecture & engineering

Who We Are

About The Standard Domain 

ISAUnited is a Standards Development Organization focused on developing, governing, publishing, and maintaining cybersecurity standards for architecture, engineering, verification, validation, and evidence-based implementation.

Our work supports practitioners and organizations that need cybersecurity expectations translated into measurable technical outcomes that can be implemented, reviewed, validated, and defended with proof.

Aboutus_intro.png

What We Develop

Standards Built for Architecture, Engineering, and Proof

The Defensible 10 Standards provide a structured standards foundation for designing, building, testing, and proving secure systems across ten cybersecurity domains.

Each standard is designed to help practitioners move from security intent to engineered outcomes through:

Why the Standards Matter

Moving Cybersecurity from Intent to Engineered Outcomes

Many cybersecurity programs rely on policies, frameworks, tools, and control checklists, but still lack a practical standards model for engineering secure systems.

ISAUnited helps close that gap by defining standards that support secure design, disciplined implementation, measurable validation, and evidence-backed assurance.

FAILURE_Patterns.png
ENG_Patterns.png
The Defensible 10 Model

In 2023, a small group of cybersecurity architects and engineers convened for a workshop with a narrow goal: study the last decade of major cyber incidents, focusing on intrusions and data leaks, and treat them as engineering failures rather than isolated events.

We approached the review the way engineers investigate disasters. We did not start with tools, vendors, or media narratives. We began with sequences: what was assumed, what was built, what changed, what was observed, what actions were possible under pressure, and what proof existed after the fact. Across industries and architectures, the same failure patterns kept resurfacing.

6 patterns repeated with uncomfortable consistency. Teams could not clearly define their scope and exposure. Security intent was not translated into explicit design decisions. Change moved into production without disciplined control. Telemetry was incomplete, delayed, or untrusted. Containment was slow, manual, or improvised. Finally, teams could not demonstrate that defenses were working, leaving leadership and practitioners relying on confidence rather than evidence.

We captured those patterns, named them, and reverse-engineered them into 6 defensible elements. We then organized them into a repeatable engineering loop that drives work from definition through demonstration. The loop is intentionally simple because it must be executed under real operational conditions, not only during audits or major incidents. The end state is not a claim of security. The end state is evidence.

That loop became the 6 Defensible Loop model. The Defensible 10 Standards became the coverage. We mapped the enterprise security surface to 10 cybersecurity domains and required the same 6 Defensible Loop (D-Loop) to be executed within each domain standard. Each standard runs the loop. Each standard ends in proof via evidence.

Standards Development and Governance

Governed for Trust. Maintained for Relevance.

ISAUnited standards are developed through a structured process that supports practitioner contribution, peer review, technical rigor, version control, validation, and long-term stewardship.

Aboutus_governed.png
D10S_ISAU_shield_logo_v2_2026_transp.png
Download Access Note

If your organization blocks file downloads, please contact us via the website or by email at info@isaunited.org.

Maintained by:

ISAUnited-red_trimmed.png

Training by:

new-1-blue-background_v2.png

Practitioner and Organizational Use

The Defensible 10 Standards (D10S) are published under a Creative Commons Attribution–NonCommercial 4.0 International License (CC BY-NC 4.0).


This license permits free use, adaptation, and internal implementation of the D10S by individual practitioners, educational institutions, and organizations for the purpose of research, training, architecture design, or internal security engineering.


Attribution to ISAUnited.org must be maintained in all uses, reproductions, or derivative works.

Commercial, Vendor, and Integration Use

The use, reproduction, or incorporation of the Defensible 10 Standards (D10S) or their content within commercial products, software, tooling, managed services, or for-profit offerings requires a separate commercial integration or redistribution license issued by the Institute of Security Architecture United (ISAUnited.org).


This includes but is not limited to:

  • Integration into commercial or subscription-based platforms or software tools

  • Use in vendor-branded frameworks or automated compliance products

  • Redistribution of modified or adapted versions for resale or commercial benefit

 

Requests for commercial licensing or integration agreements should be directed to:  info@isaunited.org

© 2026 The Defensible 10 Standards (D10S). Owned, operated, and maintained by the Institute of Security Architecture United (ISAUnited.org).

bottom of page