Information Systems Security Management Professional (ISSMP)

Information Systems Security Management Professional (ISSMP) training course

The Information Systems Security Management Professional (ISSMP) certification is an advanced-level credential offered by the International Information System Security Certification Consortium (ISC)². It’s designed for experienced security professionals who are involved in the management, leadership, and oversight of an organization’s information security program.

Benefits of ISSMP Certification

The Information Systems Security Management Professional (ISSMP) certification helps professionals develop advanced leadership and management skills in information security. Additionally, it focuses on strategic planning, governance, risk management, and security operations.

Strategic Security Planning

ISSMP helps professionals understand strategic security concepts and techniques. Furthermore, participants learn how to align security objectives with business goals and develop comprehensive security strategies.

Security Leadership and Management

The certification develops leadership abilities required for managing security programs. Moreover, professionals strengthen their skills in team management, communication, and security-related decision-making.

Risk Management and Governance

ISSMP provides knowledge of risk management approaches, including risk assessment, analysis, and mitigation strategies. Additionally, it covers security governance practices, policies, and processes that support organizational security objectives.

Compliance and Business Continuity

Professionals learn how to develop compliance frameworks and monitoring methods to support regulatory requirements. Furthermore, the certification covers business continuity planning, disaster recovery, and strategies for maintaining operations during disruptions.

Legal and Ethical Security Practices

ISSMP also addresses legal, regulatory, and ethical considerations in information security management. As a result, professionals gain awareness of privacy requirements, intellectual property protection, and ethical responsibilities.

Target Audience for ISSMP

The Information Systems Security Management Professional (ISSMP) certification is designed for professionals responsible for managing, leading, and supporting information security programs. Additionally, it is suitable for individuals involved in security strategy, governance, and risk management.

The program is ideal for:

  • Information Security Managers – Professionals responsible for developing and managing security strategies and programs.
  • Security Consultants – Specialists advising organizations on security management and best practices.
  • IT Managers and Directors – Leaders overseeing technology operations, security initiatives, and governance.
  • Risk Management Professionals – Individuals involved in identifying, assessing, and managing security risks.
  • Security Program Managers – Professionals responsible for planning and executing security programs.
  • System and Network Administrators – Technical professionals supporting secure system and network operations.

Pre-Requisites

To pursue the Information Systems Security Management Professional (ISSMP) certification, candidates must meet specific experience requirements in information security management.

Candidates must meet one of the following criteria:

  • Hold CISSP certification in good standing and have at least two years of full-time experience in one or more ISSMP domains.

OR

  • Have a minimum of seven years of full-time experience across two or more ISSMP domains. Additionally, a relevant bachelor’s or master’s degree, or an approved ISC² credential, may satisfy one year of the required experience.

Part-time work and internships may also contribute toward meeting the required experience criteria.

Exam Name  Information Systems Security Management Professional (ISSMP)
Exam Type  Multiple-choice Questions 
Exam Cost  Exam Fee*: $599.00 + Application Fee: $150.00 
Total Questions  125 Questions 
Exam Duration  3 Hours (180 Minutes)
Languages  English, French, German, Brazilian, Portuguese, Spanish, Japanese 
COURSE SYLLABUS

1.1 Establish Security’s Role in Organizational Culture, Vision, and Mission

Participants will learn how to align information security with organizational goals, values, and business processes. Additionally, they will understand the role of security within the broader organizational culture.

Topics include:

  • Defining security program vision and mission
  • Aligning security with organizational objectives
  • Understanding security’s relationship with business processes and culture

1.2 Align Security Program with Organizational Governance

This section focuses on integrating security programs with organizational governance structures. Furthermore, participants will learn how to engage stakeholders and gain support for security initiatives.

Topics include:

  • Navigating governance structures
  • Validating stakeholder roles and authorization boundaries
  • Supporting organizational security initiatives

1.3 Define and Implement Information Security Strategies

Participants will explore methods for developing and managing effective security strategies. Additionally, they will learn how to align security requirements with business initiatives.

Topics include:

  • Identifying security requirements
  • Evaluating implementation capabilities
  • Managing and reviewing security strategies
  • Applying security architecture and engineering concepts

1.4 Define and Maintain Security Policy Framework

This section covers the development and maintenance of security policies and standards. Moreover, participants will learn how to establish frameworks that support compliance and protection requirements.

Topics include:

  • Identifying external standards
  • Defining data classification and protection requirements
  • Developing policies, procedures, standards, and guidelines
  • Reviewing security policy frameworks

1.5 Manage Security Requirements in Contracts and Agreements

Participants will learn how to manage security considerations within contracts and service agreements. Furthermore, they will understand how to address compliance and risk requirements.

Topics include:

  • Evaluating service management agreements
  • Governing managed services
  • Managing organizational change impacts
  • Monitoring contractual compliance

1.6 Manage Security Awareness and Training Programs

This section focuses on developing security awareness programs that improve organizational security culture.

Topics include:

  • Promoting security programs
  • Implementing targeted training programs
  • Measuring training effectiveness

1.7 Define, Measure, and Report Security Metrics

Participants will learn how to use security metrics to evaluate performance and support decision-making.

Topics include:

  • Identifying Key Performance Indicators (KPIs)
  • Linking KPIs to organizational risk posture
  • Using metrics to improve security operations

1.8 Prepare, Obtain, and Administer Security Budget

This section covers financial management for security programs. Additionally, participants will learn how to plan budgets based on organizational risks and priorities.

Topics include:

  • Preparing security budgets
  • Adjusting budgets based on risks and threats
  • Managing financial reporting responsibilities

1.9 Manage Security Programs

Participants will explore methods for managing security teams and improving collaboration. Furthermore, they will learn how to resolve conflicts and strengthen cross-functional relationships.

Topics include:

  • Defining roles and responsibilities
  • Managing team accountability
  • Building stakeholder relationships
  • Resolving security-related conflicts

1.10 Apply Product Development and Project Management Principles

This section focuses on integrating security into project and product development processes. Additionally, participants will learn how to apply project management principles to security initiatives.

Topics include:

  • Incorporating security into project lifecycles
  • Applying project management methodologies
  • Managing project scope, time, and cost relationships

2.1 Manage Integration of Security into Systems Development Life Cycle (SDLC)

Participants will learn how to integrate security practices throughout the system development lifecycle. Additionally, they will understand how security requirements and controls support secure system development.

Topics include:

  • Integrating security requirements into lifecycle decision points
  • Implementing security controls throughout the system lifecycle
  • Managing security configuration management (CM) processes

2.2 Integrate New Business Initiatives and Emerging Technologies into Security Architecture

This section focuses on incorporating new technologies and business initiatives while maintaining security effectiveness. Furthermore, participants will learn how to assess their impact on organizational security.

Topics include:

  • Integrating security into new initiatives and technologies
  • Assessing changes to security posture
  • Aligning emerging technologies with security architecture

2.3 Define and Oversee Comprehensive Vulnerability Management Programs

Participants will explore methods for identifying, assessing, and managing vulnerabilities. Additionally, they will learn how vulnerability management supports proactive risk reduction.

Topics include:

  • Vulnerability scanning and penetration testing
  • Threat analysis
  • Asset classification and prioritization
  • Threat and vulnerability prioritization
  • Security testing management
  • Risk-based vulnerability mitigation and remediation

2.4 Manage Security Aspects of Change Control

This section covers managing security requirements during organizational and technical changes. Moreover, participants will learn how to maintain compliance and security visibility throughout the change process.

Topics include:

  • Integrating security requirements into change control
  • Coordinating with stakeholders
  • Managing documentation and tracking
  • Ensuring policy compliance through continuous monitoring

3.1 Develop and Manage a Risk Management Program

Participants will learn how to establish and manage effective risk management programs that support organizational security objectives. Additionally, they will explore methods for identifying risks, evaluating treatments, and implementing appropriate controls.

Topics include:

  • Defining risk management program objectives
  • Aligning objectives with risk owners and stakeholders
  • Establishing risk program scope
  • Identifying organizational risk tolerance and appetite
  • Maintaining asset inventory
  • Analyzing organizational risks
  • Determining countermeasures and mitigating controls
  • Performing cost-benefit analysis (CBA) for risk treatments

3.2 Conduct Risk Assessments

This section focuses on identifying and evaluating factors that influence organizational security risks. Furthermore, participants will learn how risk assessments support informed security decisions.

Topics include:

  • Identifying risk factors
  • Evaluating security risks
  • Supporting risk-based decision-making

3.3 Manage Security Risks Within the Supply Chain

Participants will learn how to identify and manage security risks related to suppliers, vendors, and third-party relationships. Additionally, they will understand the importance of integrating supply chain risks into broader organizational risk management.

Topics include:

  • Identifying supply chain security requirements
  • Integrating supply chain risks into risk management programs
  • Validating supply chain security controls
  • Monitoring and reviewing supply chain risks

4.1 Establish and Maintain Threat Intelligence Program

Participants will learn how to develop threat intelligence programs that support proactive security monitoring and decision-making. Additionally, they will explore methods for collecting, analyzing, and responding to threat information.

Topics include:

  • Gathering threat data from multiple intelligence sources
  • Establishing network, data, and user behavior baselines
  • Detecting and analyzing abnormal behavior patterns
  • Conducting threat modeling
  • Identifying and categorizing attacks
  • Correlating security events and threat data
  • Creating actionable security alerts

4.2 Establish and Maintain Incident Handling and Investigation Program

This section focuses on developing effective incident response and investigation capabilities. Furthermore, participants will learn how to manage security incidents, coordinate response activities, and identify root causes.

Topics include:

  • Developing incident response documentation
  • Establishing incident response case management processes
  • Creating and managing incident response teams
  • Applying incident management methodologies
  • Maintaining incident handling and investigation processes
  • Reporting financial and operational impacts of incidents
  • Conducting Root Cause Analysis (RCA)

5.1 Facilitate Development of Contingency Plans

Participants will learn how to develop effective contingency plans that support organizational resilience. Additionally, they will explore methods for coordinating continuity, recovery, and crisis management activities.

Topics include:

  • Analyzing factors related to Continuity of Operations Plan (COOP)
  • Developing Business Continuity Plans (BCP)
  • Developing Disaster Recovery Plans (DRP)
  • Coordinating contingency plans with stakeholders
  • Establishing crisis communication plans
  • Defining contingency roles and responsibilities
  • Assessing impacts on business processes and priorities
  • Managing third-party dependencies
  • Preparing security management succession plans

5.2 Develop Recovery Strategies

This section focuses on creating recovery approaches that help organizations restore operations effectively. Furthermore, participants will learn how to evaluate alternatives and assign recovery responsibilities.

Topics include:

  • Identifying and analyzing recovery alternatives
  • Recommending recovery strategies
  • Coordinating recovery activities
  • Assigning recovery roles and responsibilities

5.3 Maintain Contingency Plans, COOP, BCP, and DRP

Participants will learn how to review and improve continuity and recovery plans over time. Additionally, they will understand the importance of testing and maintaining organizational resilience.

Topics include:

  • Planning testing, evaluation, and modifications
  • Assessing survivability and resiliency capabilities
  • Managing plan updates

5.4 Manage Disaster Response and Recovery Process

This section covers the processes required to respond to disasters and restore normal operations. Moreover, participants will learn how lessons learned improve future preparedness.

Topics include:

  • Declaring disasters
  • Implementing response plans
  • Restoring normal operations
  • Capturing lessons learned
  • Updating plans based on improvements identified

6.1 Identify the impact of laws and regulations that relate to information security 

» Identify applicable privacy laws 

» Identify legal jurisdictions the organization and 

users operate within (e.g., trans-border data flow) 

» Identify export laws 

» Identify intellectual property (IP) laws 

» Identify applicable industry regulations 

» Identify and advise on non-compliance risks 

6.2 Adhere to the (ISC)2 Code of Ethics as related to management issues 

6.3 Validate compliance in accordance with applicable laws, regulations and industry 

best practices 

» Inform and advise senior management 

» Evaluate and select compliance framework(s) 

» Implement the compliance framework(s) 

» Define and monitor compliance metrics 

6.4 Coordinate with auditors and regulators in support of the internal and external 

audit processes 

» Plan 

» Schedule 

» Coordinate audit activities 

» Evaluate and validate findings 

» Formulate response 

» Validate implemented mitigation and remediation actions 

6.5 Document and manage compliance exceptions 

» Identify and document compensating controls and workarounds 

» Report and obtain authorized approval of risk waiver 

Benefits of ISSMP Certification

The Information Systems Security Management Professional (ISSMP) certification helps professionals strengthen their expertise in information security leadership, strategic planning, and risk management. Additionally, it demonstrates advanced capabilities in managing and improving security programs.

Competence Recognition

ISSMP certification validates professionals’ knowledge and skills in information security program management. Furthermore, it demonstrates expertise in areas such as strategic planning, leadership, and risk management.

Career Progression

The certification can support career growth in information security management roles. Moreover, it can help professionals pursue advanced positions such as Chief Information Security Officer (CISO) or Senior Security Manager.

Strategic Security Leadership

ISSMP helps professionals develop the ability to plan and implement security initiatives aligned with organizational goals. As a result, participants can improve the effectiveness and resilience of information security programs.

Risk Management Proficiency

Professionals gain the ability to identify, assess, and reduce information security risks. Additionally, this knowledge supports proactive risk management and helps protect critical organizational assets.

Credibility and Networking Opportunities

ISSMP certification enhances professional credibility by demonstrating commitment to security excellence and industry best practices. Furthermore, it provides opportunities to connect with a global community of information security professionals through organizations such as (ISC)².

Up-coming Schedule: 

Please contact us to know about the upcoming schedule.