Information Systems Security Engineering Professional (ISSEP)

 Information Systems Security Engineering Professional (ISSEP)

The Information Systems Security Engineering Professional (ISSEP) certification is an advanced-level credential offered by (ISC)², a leading global cybersecurity organization. ISSEP focuses on the integration of security into the information systems lifecycle process.

The Information Systems Security Engineering Professional (ISSEP) is a security leader who specializes in the practical application of systems engineering principles and processes to develop secure systems. An ISSEP analyzes organizational needs, defines security requirements, designs security architectures, develops secure designs, implements system security, and supports system security assessment and authorization for government and industry.
The broad spectrum of topics included in the ISSEP body of knowledge ensure its relevancy across all disciplines in the field of security engineering. Successful candidates are competent in the following five domains:
• Systems Security Engineering Foundations
• Risk Management
• Security Planning and Design
• Systems Implementation, Verification and Validation
• Secure Operations, Change Management and Disposal

  • Chief Information Security Officer
  • Chief Information Officer
  • Director of Security
  • IT Director/Manager
  • Security Systems Engineer
  • Security Analyst
  • Security Manager
  • Security Auditor
  • Security Architect
  • Security Consultant
  • Network Architect

Pre-Requisites 

Candidates must be a CISSP in good standing and have two years’ cumulative, full-time experience in one or more of the five domains of the current ISSEP outline.
Or
Candidates must have a minimum of seven years’ cumulative, full-time experience in two or more of the domains of the current ISSEP outline. Earning a post-secondary degree (bachelor’s or master’s) in computer science, information technology (IT) or related fields or an additional credential from the ISC2 approved list may satisfy one year of the required experience. Part-time work and internships may also count towards the experience requirement.

Exam Information 

Exam Name  Information Systems Security Engineering Professional (ISSEP)
Exam Type Multiple-choice Questions
Total Questions 125 Questions
Exam Duration 3 Hours
Passing Score 700 out of 1000
Languages  English
Testing center Pearson VUE Testing Center
Course Duration : 5 Days 
Course Syllabus

1.1 Apply systems security engineering fundamentals

» Understand systems security engineering trust concepts and hierarchies
» Identify the relationships between systems and security engineering processes

» Apply structural security design principles

1.2 Execute systems security engineering processes

» Identify organizational security authority
» Identify system security policy elements

» Integrate design concepts (e.g., open, proprietary, modular)

1.3 Integrate with applicable system development methodology

» Integrate security tasks and activities
» Verify security requirements throughout the process

» Integrate software assurance methods

1.4 Perform technical management

Perform project planning processes
» Perform project assessment and control processes
» Perform decision management processes
» Perform risk management processes
» Perform configuration management processes

» Perform information management processes
» Perform measurement processes
» Perform Quality Assurance (QA) processes
» Identify opportunities for security process automation

1.5 Participate in the acquisition process

» Prepare security requirements for acquisitions
» Participate in selection process
» Participate in Supply Chain Risk Management (SCRM)

» Participate in the development and review of contractual documentation

1.6 Design Trusted Systems and Networks (TSN)

2.1 Apply security risk management principles
2.2 Address risk to system
2.3 Manage risk to operations
» Establish risk context
» Identify system security risks
» Perform risk analysis
» Perform risk evaluation
» Recommend risk treatment options
» Document risk findings and decisions
» Determine stakeholder risk tolerance
» Identify remediation needs and other system changes
» Determine risk treatment options
» Assess proposed risk treatment options
» Recommend risk treatment options

3.1 Analyze organizational and operational environment

» Capture stakeholder requirements
» Identify relevant constraints and assumptions
» Assess and document threats

» Determine system protection needs
» Develop Security Test Plans (STP)

3.2 Apply system security principles

Incorporate resiliency methods to address threats
» Apply defense-in-depth concepts
» Identify fail-safe defaults
» Reduce Single Points of Failure (SPOF)

» Incorporate least privilege concept
» Understand economy of mechanism
» Understand Separation of Duties (SoD) concept

3.3 Develop system requirements

» Develop system security context
» Identify functions within the system and security Concept of Operations (CONOPS)

» Document system security requirements baseline
» Analyze system security requirements

3.4 Create system security architecture and design

Develop functional analysis and allocation
» Maintain traceability between specified design and system requirements

» Develop system security design components
» Perform trade-off studies
» Assess protection effectiveness

4.1 Implement, integrate and deploy security solutions
4.2 Verify and validate security solutions
» Perform system security implementation and integration
» Perform system security deployment activities
» Perform system security verification
» Perform security validation to demonstrate security controls meet stakeholder security requirements

5.1 Develop secure operations strategy
5.2 Participate in secure operations
5.3 Participate in change management
5.4 Participate in the disposal process
» Specify requirements for personnel conducting operations
» Contribute to the continuous communication with stakeholders for security relevant aspects of the system
» Develop continuous monitoring solutions and processes
» Support the Incident Response (IR) process
» Develop secure maintenance strategy
» Participate in change reviews
» Determine change impact
» Perform verification and validation of changes
» Update risk assessment documentation
» Identify disposal security requirements
» Develop secure disposal strategy
» Develop decommissioning and disposal procedures
» Audit results of the decommissioning and disposal process

  • Advanced Expertise: ISSEP certification showcases your specialized knowledge in designing, developing, and managing security solutions for information systems.
  • Career Advancement: Differentiate yourself in the competitive cybersecurity landscape and unlock opportunities for higher-level roles and responsibilities.
  • Industry Recognition: Gain credibility and recognition from employers, clients, and peers as a trusted expert in Information Systems Security Engineering.
  • Comprehensive Skillset: Acquire a comprehensive skill set covering security engineering principles, risk management, and secure system architecture design.
  • Global Opportunities: Expand your career horizons globally, as ISSEP certification is recognized and valued across industries and geographic regions.

Up-coming Schedule: 

Please contact us to know about the upcoming schedule.