top of page
D10S_hero_bkgd_v1_2026.png

Standards Library

The Parent Standards

The Defensible 10 Parent Standards define the measurable architecture, engineering, verification, and evidence foundation for building secure, resilient, and defensible systems.

hero_parent_pg_image.png

D10S Three-Tier Program

Parent Standard

Defines the domain requirements, principles, and intended outcomes.

Domain foundation

Shield_icon_blue1.png
D10S-3tier_pic1.png
Leadership Brochure
D01

D01

Published - 2026 

Network Security Architecture & Engineering

Defines how to design and engineer segmented, resilient network architectures that enforce least privilege, prevent lateral movement, and enable measurable control across hybrid infrastructures.

GH_pic.jpg

D02

Published - 2026

Cloud Security Architecture & Resilience

Guides practitioners in architecting cloud environments with integrated Zero Trust controls, automated security enforcement, and resilient multi-cloud design patterns.

GH_pic.jpg

D03

Published - 2026

Compute, Platform & Workload Security Architecture

Establishes engineering principles for securing compute resources, platforms, and workloads through hardened configurations, runtime protection, and workload integrity validation.

GH_pic.jpg

D04

Published - 2026

Application Security Architecture & Secure Development

Provides a structured framework for embedding security by design into software architecture, ensuring applications are built, tested, and deployed with defensible assurance.

GH_pic.jpg

D05

Published - 2026

Data Security Architecture
 

Outlines engineering controls for protecting data throughout its lifecycle, including classification, encryption, governance, and secure data handling across distributed systems.

GH_pic.jpg

D06

Published - 2026

Identity & Access Security Architecture

Defines architectural and engineering methods to enforce Zero Trust identity, adaptive authentication, and privileged access management across enterprise systems.

GH_pic.jpg

D07

Published - 2026

Threat & Vulnerability Security Engineering

Establishes a proactive engineering discipline for identifying, modeling, and mitigating threats through continuous vulnerability analysis, attack surface reduction, and validation.

GH_pic.jpg

D08

Published - 2026

Monitoring, Detection & Incident Response Architecture

Defines the architecture and operational design for real-time detection, telemetry integration, and automated incident response across hybrid and cloud-native environments.

GH_pic.jpg

D09

Published  - 2026

Cryptography, Encryption & Key Management

Provides the engineering foundation for implementing secure cryptographic systems, key management lifecycles, and encryption standards that ensure data integrity and confidentiality.

GH_pic.jpg

D10

Published - 2026

DevSecOps & Secure SDLC Engineering

Integrates security automation, validation, and compliance into CI/CD pipelines, ensuring software and infrastructure are engineered for security at every stage of development.

GH_pic.jpg
D10
D10S_ISAU_shield_logo_v2_2026_transp.png
Download Access Note

If your organization blocks file downloads, please contact us via the website or by email at info@isaunited.org.

Governance by:

ISAUnited-red_trimmed.png

Training by:

  • LinkedIn

Practitioner and Organizational Use

The Defensible 10 Standards (D10S) are published under a Creative Commons Attribution–NonCommercial 4.0 International License (CC BY-NC 4.0).


This license permits free use, adaptation, and internal implementation of the D10S by individual practitioners, educational institutions, and organizations for the purpose of research, training, architecture design, or internal security engineering.


Attribution to ISAUnited.org must be maintained in all uses, reproductions, or derivative works.

Commercial, Vendor, and Integration Use

The use, reproduction, or incorporation of the Defensible 10 Standards (D10S) or their content within commercial products, software, tooling, managed services, or for-profit offerings requires a separate commercial integration or redistribution license issued by the Institute of Security Architecture United (ISAUnited.org).


This includes but is not limited to:

  • Integration into commercial or subscription-based platforms or software tools

  • Use in vendor-branded frameworks or automated compliance products

  • Redistribution of modified or adapted versions for resale or commercial benefit

 

Requests for commercial licensing or integration agreements should be directed to:  info@isaunited.org

© 2026 The Defensible 10 Standards (D10S). Owned, operated, and maintained by the Institute of Security Architecture United (ISAUnited.org).

bottom of page