We architect
your knowledge.
A cyber security academy in Chennai. We train practitioners the long way — daily, under a fixed standard — starting with a hundred-day programme for the ISSAP examination.
A message from our Founder
On why an academy for architects, and what we ask of the people who study here.
There is no shortage of places to learn security. There is a shortage of places that teach judgement — the thing that decides whether a design holds when the budget is cut, the deadline moves and the person who wrote the requirement has left.
Raksham was built for that gap. We are named for the Sanskrit root that means to protect, and we are unusually literal about the second half of our promise: architecture is a discipline of drawings, constraints and defended decisions, and it can be taught the way architecture has always been taught — by working, every day, under a standard that does not move.
So we ask a great deal. A hundred days, six of teaching and one of revision each week. A written reasoning drill every day, in your own words, before you see ours. A quiz you may retake as often as you like, because the point was never the score on the first attempt. Four mastery checks you cannot route around. Our certificate is issued on evidence, not attendance, and we would rather award fewer of them.
If you are willing to work at that standard, we would be glad to have you. Everything we know is in the programme, and my door is open to anyone studying here.
What makes a Raksham day
The same five parts, a hundred times. The rhythm is the method.
A narrated tutorial
A presentation that plays itself — slides, a spoken lecture and a drawn diagram of the day's idea, with the full script underneath.
Study notes
Tables, exam traps and vocabulary, written for the 2025 ISSAP outline rather than adapted from a CISSP course.
The PUNCH drill
A scenario you answer in writing before the model answer unlocks. Problem, Users, Non-negotiables, Choices, Hold the line.
A quiz
Five questions with an explanation for every distractor, not just the key. Retake it as often as you like.
Further reading
Four to six primary sources a day — the NIST publications, the standards and the frameworks themselves, not summaries of them.
Revision
The seventh day of each week revisits the six before it. Days 21, 42, 77 and 98 add a mastery check on the whole domain.
Our first programme
A cyber security academy earns the name one course at a time. We would rather run a single programme properly than a catalogue badly.
The 100-Day ISSAP Programme
Complete preparation for the ISC2 Information Systems Security Architecture Professional examination, mapped to the outline effective 1 August 2025. Fifteen weeks. Five hundred assessment items. Instructor-approved enrolment.
A cyber security academy
that teaches judgement.
Raksham Academy trains cyber security practitioners — defenders, engineers, consultants and the architects they become. Our first programme is a hundred days on security architecture, because that is where judgement is hardest to teach and most valuable to have. It will not be our last.
What we believe
Most security training optimises for the exam and hopes the understanding follows. We think that is backwards, and expensive: a candidate who memorises the answer to a question about compensating controls has learned nothing they can use on a Monday morning.
So the whole programme teaches one habit from four directions, and says so out loud on the last day: refuse to let a word, a number or a document stand in for a mechanism you have not verified. A flattering metric. An acceptance nobody signed. A control that was described but never tested. A protocol named in a diagram that nobody has traced end to end.
The examination happens to reward exactly that habit. That is a convenience, not the purpose.
Who it is for
The ISSAP is a concentration for people who already hold the CISSP. The programme assumes that starting point.
- Security engineers moving into design. You build and operate today, and you are being asked to decide rather than implement.
- Consultants who own the diagram. You already produce architecture, and you want the vocabulary and the frameworks behind what you draw.
- SOC and infrastructure leads. You understand one layer deeply and need the whole stack — governance through identity — to hold a design conversation.
- CISSP holders taking the concentration. You want a structured hundred days rather than a fortnight of cramming before the appointment.
How we teach
Daily, not intensive
A hundred consecutive days beats a bootcamp. Retention is a function of spacing, and the syllabus is built around that fact rather than around a training calendar.
Write before you read
Every day asks for your reasoning in writing before the model answer is available. Producing an argument and then comparing it is the exercise.
Primary sources
You read NIST SP 800-207, the OWASP list, the PCI quick reference and the framework guides themselves. We annotate them; we do not replace them.
Measured progress
Your instructor sees every student's board — days complete, quiz averages, mastery checks — and can amend any day's material for the whole cohort in minutes.
Small batches
Enrolment is approved individually and students are assigned to a named batch, so nobody is a row in a spreadsheet of ten thousand.
Evidence, then certificate
The certificate needs all hundred days complete, a 75% assessment average and every mastery check passed at 80%. It is checkable by number.
What comes after ISSAP
We will announce a course when it is written, not when it is planned. Nothing below is open for enrolment.
ISSAP — 100 days
Security architecture, the full ISC2 concentration. Enrolling now.
Detection engineering
Building and tuning what a SOC actually runs on: data sources, normalisation, detection logic, and the evidence a detection produces.
Security operations foundation
The entry route — triage, escalation, and the discipline of writing down what you saw and what you did about it.
Where we are
Raksham Academy is based in Chennai, Tamil Nadu, and teaches online. The programme runs in English and is designed to fit around full-time work — a working day at Raksham is about ninety minutes.
The 100-Day
ISSAP Programme
Complete preparation for the ISC2 Information Systems Security Architecture Professional examination, mapped to the outline effective 1 August 2025 — fourteen weeks of six teaching days and one revision day, then a two-day final approach.
The four domains
Time on each domain is allocated in proportion to its weight in the examination.
| Weeks | Domain | Exam weight | Covered |
|---|---|---|---|
| 1 – 3 | Governance, Risk & Compliance | 21% | Obligations, risk assessment and treatment, monitoring, audit architecture, forensics, policy hierarchy, classification, continuity, cloud governance, change |
| 4 – 6 | Security Architecture Modeling | 22% | Zachman, TOGAF and SABSA, reference architectures, threat modeling, STRIDE, CVSS, ATT&CK, verification and validation, code review |
| 7 – 11 | Infrastructure & System Security | 32% | Deployment models, IT and OT, physical and environmental, platform, network segmentation, core services, storage, cloud, zero trust, endpoints, OT/IoT, monitoring, cryptography and key management |
| 12 – 14 | Identity & Access Management | 25% | Identity lifecycle, proofing, authentication protocols, federation, trust, authorization models, privileged access, single sign-on, accounting and compliance logging |
| 99 – 100 | Final approach | — | A full 125-item mock under examination conditions with error-type analysis, then exam-day readiness and the architect's final brief |
Week by week
| Week | Theme | Week | Theme |
|---|---|---|---|
| 01 | Governance Foundations | 09 | Services, Storage & Cloud |
| 02 | Architecting for GRC | 10 | Endpoints, OT & Monitoring |
| 03 | Domain 1 Integration · mastery | 11 | Cryptographic Architecture · mastery |
| 04 | Architecture Frameworks | 12 | Identity & Authentication |
| 05 | Threat Modeling | 13 | Federation & Authorization |
| 06 | Verification & Validation · mastery | 14 | Accounting & Compliance · mastery |
| 07 | Infrastructure Requirements | 15 | Final Approach |
| 08 | Platform & Network | — | — |
Assessment and the certificate
Nothing here is awarded for attendance.
- Every day. Five quiz items with an explanation for each distractor. Best score stands; retakes are unlimited.
- Every seventh day. Revision across the week just taught.
- Days 21, 42, 77 and 98. A mastery check on the whole domain, which must be passed at 80%.
- Day 99. A full-length 125-item mock over three hours, followed by error-type analysis.
What a certificate requires
All hundred days complete — studied, quiz passed, drill written. An assessment average of 75% or better across the programme. All four mastery checks passed at 80%.
With Distinction at a 90% average and 90% on every mastery check.
Each certificate carries a number your instructor can verify. It records what you did at Raksham; it is not an ISC2 credential and does not substitute for sitting the examination.
How enrolment works
Places are approved individually. There is no self-service checkout.
- Ask about the next batch. Tell us where you are today and when you intend to sit the examination.
- Register on the portal. Create your account. You will see nothing of the programme yet.
- We approve you and assign a batch. Your instructor reviews the request and opens the hundred days for you.
- Day 1. The board opens. Your progress, quiz scores and written drills are yours and visible to your instructor.
The student portal is hosted inside Raksham's own Claude workspace, so the sign-in screen is reachable to accounts in that workspace. Ask us first and we will tell you exactly how your access is set up.
Five parts, a hundred times.
Every study day at Raksham has the same shape. The repetition is deliberate: once the structure is invisible, all of the attention goes to the material.
The tutorial plays itself
Each day opens on a presentation that narrates its own slides and advances on its own, with subtitles under the frame and the written lecture script below it. You can drive it by hand, change the voice, run it at 1.25× or put it full screen.
Slide three of every deck is a drawing: the day's idea reduced to its shape. Zachman and SABSA as matrices. The TOGAF ADM and the key lifecycle as rings. The Purdue model and the certification hierarchy as stacks. STRIDE as threats paired against the property each one takes.
Day 12 · The audit chain
Requirement → Control → Test → Evidence → Opinion
Five nodes, one line of the lecture, and the reason candidates lose the question: they stop at the control and never ask what the control produces.
PUNCH — the reasoning drill
The part of the day that most resembles the job.
Problem
What is actually being asked, stripped of the way the stakeholder phrased it.
Users and stakeholders
Who is affected, who decides, and who will live with the consequence.
Non-negotiables
The obligations, constraints and safety properties that no option may violate.
Choices
The real options and what each one costs. An architect who presents one option has not done the work.
Hold the line
What you would refuse, and how you would say so to the person who outranks you.
Then compare
Only after you have written your answer does the model reasoning unlock, along with a note on where candidates go wrong.
Four tie-break questions
Taught on the last day, for the moment in an examination when two options both look defensible.
- Does it trace to the stated driver? An elegant control with no obligation behind it is an expensive opinion.
- Does it produce evidence? A control nobody can demonstrate is indistinguishable from one that was never built.
- Does the accountable owner still decide? An architect advises. The answer that quietly makes the decision for the business is usually wrong.
- Does it address the cause? Detection is not treatment. Ask what would have had to be true for the problem not to exist.
The library
Roughly five hundred references across the programme, weighted towards primary sources.
NIST
SP 800-207 and 800-207A on zero trust, 800-63 on digital identity, 800-125 on virtualisation, 800-192 on access control verification.
Frameworks
Zachman, TOGAF and SABSA study summaries, the CSA Software Defined Perimeter guide, the Cloud Controls Matrix reference architecture.
Standards and practice
The PCI DSS quick reference, the OWASP Top 10, the ISSAP examination outline itself, and case material worked in class.
Course material inside the portal is view-only and watermarked with the reading student's own address. The certificate is the single exception: that one page is yours to print.
Ask about the next batch.
Tell us where you are today — what you do, whether you hold the CISSP, and when you intend to sit the ISSAP. We will tell you honestly whether the programme is the right hundred days for you.
Reach us
- PLACEHOLDER — enquiries@yourdomain.com
- Phone
- PLACEHOLDER — +91 XXXXX XXXXX
- PLACEHOLDER — +91 XXXXX XXXXX
- Address
- PLACEHOLDER — street address
Guduvancherry, Chennai, Tamil Nadu, India - Hours
- PLACEHOLDER — e.g. Mon–Sat, 10:00–19:00 IST
- PLACEHOLDER — company page URL
Every field marked PLACEHOLDER is waiting for a real value. Search the page source for the word to find them all.
What to tell us
Four lines is plenty. It lets us answer properly rather than send a brochure.
- Your role today. What you build, operate or advise on now.
- Your certifications. The ISSAP is a CISSP concentration, so tell us where you stand with that.
- Your target exam date. A hundred days is a hundred days. We will work backwards from your date.
- Your batch preference. Whether you would rather start with the next cohort or wait for one that suits your calendar.
Already enrolled
Sign in to the portal for your board, your day and your progress. If you registered and are waiting, your instructor reviews new requests regularly — the portal will tell you the moment you are approved.