Information Systems Security Engineering Professional (ISSEP)

Information Systems Security Engineering Professional (ISSEP)

Advanced Cybersecurity Engineering Certification

The Information Systems Security Engineering Professional (ISSEP) certification is an advanced-level credential offered by (ISC)², a leading global cybersecurity organization.

Additionally, ISSEP focuses on integrating security throughout the information systems lifecycle. The certification helps professionals develop expertise in applying security engineering principles to design, implement, and manage secure systems.

Program Overview

The Information Systems Security Engineering Professional (ISSEP) certification focuses on applying systems engineering principles and processes to develop secure systems. Additionally, ISSEP professionals analyze organizational needs, define security requirements, design security architectures, and support security assessments.

The ISSEP body of knowledge covers a broad range of security engineering topics. Furthermore, successful candidates develop expertise across five key domains:

  • Systems Security Engineering Foundations
  • Risk Management
  • Security Planning and Design
  • Systems Implementation, Verification, and Validation
  • Secure Operations, Change Management, and Disposal

These domains help professionals strengthen their ability to design, implement, and maintain secure information systems across government and industry environments.

Who Should Attend?

This Information Systems Security Engineering Professional (ISSEP) program is suitable for cybersecurity, IT, and security professionals involved in designing, managing, and protecting information systems.

The program is ideal for:

  • Chief Information Security Officers (CISOs) – Leaders responsible for developing and managing cybersecurity strategies.
  • Chief Information Officers (CIOs) – Executives overseeing information technology strategy and governance.
  • Security Directors and Managers – Professionals managing security operations, policies, and risk.
  • IT Directors and Managers – Individuals responsible for IT infrastructure and system security.
  • Security Systems Engineers – Specialists involved in secure system design and implementation.
  • Security Analysts and Auditors – Professionals assessing security controls and compliance requirements.
  • Security Architects – Experts designing secure system architectures.
  • Security Consultants – Advisors supporting organizations with security solutions.
  • Network Architects – Professionals responsible for developing secure network environments.

Pre-Requisites 

Candidates must be a CISSP in good standing and have two years’ cumulative, full-time experience in one or more of the five domains of the current ISSEP outline.
Or
Candidates must have a minimum of seven years’ cumulative, full-time experience in two or more of the domains of the current ISSEP outline. Earning a post-secondary degree (bachelor’s or master’s) in computer science, information technology (IT) or related fields or an additional credential from the ISC2 approved list may satisfy one year of the required experience. Part-time work and internships may also count towards the experience requirement.

Exam Information 

Exam Name  Information Systems Security Engineering Professional (ISSEP)
Exam Type Multiple-choice Questions
Total Questions 125 Questions
Exam Duration 3 Hours
Passing Score 700 out of 1000
Languages  English
Testing center Pearson VUE Testing Center
Course Duration : 5 Days 
Course Syllabus

1.1 Apply Systems Security Engineering Fundamentals

Participants will learn core security engineering concepts and how they support secure system development.

Topics include:

  • Systems security engineering trust concepts and hierarchies
  • Relationships between systems and security engineering processes
  • Structural security design principles

1.2 Execute Systems Security Engineering Processes

This section focuses on applying security engineering processes within organizational environments. Furthermore, participants will understand security authority, policies, and design approaches.

Topics include:

  • Organizational security authority
  • System security policy elements
  • Open, proprietary, and modular design concepts

1.3 Integrate with Applicable System Development Methodology

Participants will learn how to incorporate security throughout the system development lifecycle.

Topics include:

  • Security tasks and activities
  • Verification of security requirements
  • Software assurance methods

1.4 Perform Technical Management

This section covers the management activities required to support secure system engineering. Additionally, participants will explore planning, assessment, control, and improvement processes.

Topics include:

  • Project planning and assessment
  • Decision and risk management
  • Configuration and information management
  • Measurement and quality assurance processes
  • Security process automation opportunities

1.5 Participate in the Acquisition Process

Participants will learn how security requirements are integrated into acquisition activities.

Topics include:

  • Preparing security requirements
  • Supporting selection processes
  • Supply Chain Risk Management (SCRM)
  • Reviewing contractual documentation

1.6 Design Trusted Systems and Networks (TSN)

Participants will explore principles for designing trusted systems and networks that support secure operations and risk management.

2.1 Apply Security Risk Management Principles

Participants will learn how to apply security risk management principles to identify, assess, and address cybersecurity risks. Additionally, they will understand how effective risk management supports secure decision-making.

Topics include:

  • Establishing risk context
  • Identifying system security risks
  • Performing risk analysis and evaluation
  • Recommending risk treatment options
  • Documenting risk findings and decisions
  • Determining stakeholder risk tolerance

2.2 Address Risk to Systems

This section focuses on identifying and managing risks that affect system security. Furthermore, participants will learn how to evaluate risks and determine appropriate responses.

Topics include:

  • Identifying remediation needs
  • Assessing system changes
  • Determining suitable risk treatment options
  • Evaluating proposed risk treatments

2.3 Manage Risk to Operations

Participants will explore methods for managing operational risks and maintaining secure system performance. As a result, they will develop the ability to support effective risk-based decisions.

Topics include:

  • Assessing risk treatment options
  • Recommending risk management actions
  • Supporting secure operational processes

3.1 Analyze Organizational and Operational Environment

Participants will learn how to evaluate organizational environments and identify security requirements. Additionally, they will explore how stakeholder needs, constraints, and threats influence system security planning.

Topics include:

  • Capturing stakeholder requirements
  • Identifying constraints and assumptions
  • Assessing and documenting threats
  • Determining system protection needs
  • Developing Security Test Plans (STP)

3.2 Apply System Security Principles

This section focuses on applying security principles to strengthen system protection. Furthermore, participants will learn methods for improving resilience and reducing security risks.

Topics include:

  • Applying resiliency methods
  • Defense-in-depth concepts
  • Fail-safe defaults
  • Reducing Single Points of Failure (SPOF)
  • Least privilege principles
  • Economy of mechanism
  • Separation of Duties (SoD)

3.3 Develop System Requirements

Participants will learn how to define and analyze security requirements throughout system development. Additionally, they will understand how to establish security baselines and operational requirements.

Topics include:

  • Developing system security context
  • Identifying system functions and security Concept of Operations (CONOPS)
  • Documenting security requirements baselines
  • Analyzing system security requirements

3.4 Create System Security Architecture and Design

This section covers the development of secure system architectures and design components. Moreover, participants will learn how to maintain alignment between security requirements and system design.

Topics include:

  • Functional analysis and allocation
  • Maintaining traceability between design and requirements
  • Developing security design components
  • Performing trade-off studies
  • Assessing protection effectiveness

4.1 Implement, Integrate, and Deploy Security Solutions

Participants will learn how to apply security solutions throughout system implementation and deployment processes. Additionally, they will explore methods for integrating security controls effectively within systems.

Topics include:

  • System security implementation and integration
  • System security deployment activities

4.2 Verify and Validate Security Solutions

This section focuses on assessing whether security solutions meet required standards and stakeholder expectations. Furthermore, participants will learn how to verify security controls and validate system security effectiveness.

Topics include:

  • System security verification
  • Security validation activities
  • Demonstrating security controls meet stakeholder requirements

5.1 Develop Secure Operations Strategy

Participants will learn how to establish strategies that support secure system operations. Additionally, they will explore operational requirements, stakeholder communication, and continuous monitoring approaches.

Topics include:

  • Defining personnel requirements for secure operations
  • Communicating security-related information with stakeholders
  • Developing continuous monitoring solutions and processes
  • Supporting the Incident Response (IR) process
  • Creating secure maintenance strategies

5.2 Participate in Secure Operations

This section focuses on maintaining secure system operations through effective processes and controls. Furthermore, participants will understand how operational activities support system security.

Topics include:

  • Supporting secure operational activities
  • Maintaining system security processes
  • Monitoring security performance

5.3 Participate in Change Management

Participants will learn how to manage system changes while maintaining security requirements. Additionally, they will explore methods for evaluating impacts and validating changes.

Topics include:

  • Participating in change reviews
  • Determining change impact
  • Performing verification and validation of changes
  • Updating risk assessment documentation

5.4 Participate in the Disposal Process

This section covers secure system disposal and decommissioning practices. Moreover, participants will learn how to protect information and manage risks during the disposal lifecycle.

Topics include:

  • Identifying disposal security requirements
  • Developing secure disposal strategies
  • Creating decommissioning and disposal procedures
  • Auditing disposal process results
  • Advanced Expertise: ISSEP certification showcases your specialized knowledge in designing, developing, and managing security solutions for information systems.
  • Career Advancement: Differentiate yourself in the competitive cybersecurity landscape and unlock opportunities for higher-level roles and responsibilities.
  • Industry Recognition: Gain credibility and recognition from employers, clients, and peers as a trusted expert in Information Systems Security Engineering.
  • Comprehensive Skillset: Acquire a comprehensive skill set covering security engineering principles, risk management, and secure system architecture design.
  • Global Opportunities: Expand your career horizons globally, as ISSEP certification is recognized and valued across industries and geographic regions.

Up-coming Schedule: 

Please contact us to know about the upcoming schedule.