Training course
This is a free, self-paced reading course for ISSMP: Information Systems Security Management Professional: ISC2’s credential for the people who run security programs rather than build or operate the controls inside them. The ISSMP is about setting strategy, winning budgets, governing risk, directing security operations, keeping the business running through a disaster, and answering to regulators and boards. Where the CISSP proves breadth across the profession, the ISSMP proves you can lead it: aligning the program with the organization’s mission, making risk decisions defensible, and translating threats into the language of business impact. Originally a CISSP concentration, it now stands alone as one of the three highest-bar credentials ISC2 offers.
The course is organized as one module per official exam domain, in the order ISC2 publishes them, and each module carries the domain’s published weight. It follows the outline effective August 1, 2025, in which ISC2 restructured the domains around the management job as it exists now and embedded AI governance throughout, shadow AI policy, ethical governance models, the NIST AI RMF and ISO/IEC 42001, MLSecOps decision gates, prompt injection and data poisoning response, model artifacts as continuity dependencies, and the EU AI Act’s risk tiers. Read it expecting judgment questions rather than definitions: on this exam several options are usually defensible and only one is most correct.
What the course covers
Leadership and Organizational Management
Module 1 · 21%The heaviest module and the heart of the credential: establishing security’s role in culture, vision, and mission; navigating governance and the boundaries of your authority; building the policy framework of policies, standards, baselines, and guidelines; managing contracts, managed services, and the security consequences of mergers; running awareness programs that actually change behavior; defining KPIs and KRIs; preparing and defending a budget; and applying project management principles, including embedding security into agile delivery and governing the organization’s use of AI.
Systems Lifecycle Management
Module 2 · 15%Integrating security throughout the system life cycle rather than bolting it on: phase-gate governance, configuration management oversight, and folding new initiatives and emerging technology into the security architecture. The vulnerability management program lives here (asset-criticality-driven prioritization, penetration test governance, remediation and compensating controls) along with the security side of change control, from impact analysis to continuous compliance monitoring, extending to MLSecOps gates and treating model weight updates as formal system changes.
Risk Management
Module 3 · 20%The second-heaviest module: building and running the risk program, appetite and tolerance, asset inventory, qualitative and quantitative assessment with SLE, ARO, and ALE, treatment options and cost-benefit analysis, the risk register, and the question of who is actually entitled to accept a risk. Supply chain risk gets deep treatment through vendor tiering, independent attestation, fourth-party flow-downs, and continuous monitoring, joined by the NIST AI RMF, ISO/IEC 42001, generative AI procurement terms, and model weights as crown-jewel assets.
Security Operations
Module 4 · 18%Governing the operational machine: SOC charters and documentation, threat intelligence programs built on priority intelligence requirements, baselining and anomaly detection, event correlation, and engineering alerts someone will actually act on. Incident management carries equal weight, the policy-plan-playbook hierarchy, case management and chain of custody, team models, contain-first methodology, impact quantification for executives, and root cause analysis, plus prompt injection and data poisoning response, AIOps guardrails, and ML engineers as formal incident stakeholders.
Contingency Management
Module 5 · 12%Resilience from analysis through return to normal: the business impact analysis as foundation; the distinctions between COOP, BCP, and DRP; crisis communications and declaration authority; third-party and cloud dependencies; succession planning; recovery strategy selection against RTO and RPO, including the RTO + WRT ≤ MTD arithmetic; the test-type ladder from tabletop to full interruption; plan maintenance triggers; and disciplined disaster response and recovery, now with model artifacts and retraining time counted as continuity considerations.
Law, Ethics, and Security Compliance Management
Module 6 · 14%The manager as the organization’s legal and ethical conscience: mapping jurisdictions and trans-border data flows, breach notification duties, intellectual property protection for security-relevant assets including trade secrecy for model weights, and the ISC2 Code of Ethics with its ordered canons. Compliance management covers framework selection and implementation, compliance metrics, audit coordination from planning through remediation validation, and governed exception and risk waiver processes, with the EU AI Act and automated decision-making rights now in scope.
How to use it
Read the modules in order, but budget your time by weight: Leadership and Organizational Management and Risk Management together account for 41% of the exam, and they are also where the judgment questions are hardest for people who came up through technical roles. After each module, take the matching portion of the ISSMP practice exam rather than saving it for the end. The items are written at management level, so the useful signal is not whether you recognized the topic but whether you picked the option an accountable security executive would defend. The free ISSMP sample shows that question style with no account needed.
Reading the course itself requires a free Certifym account. For exam logistics (the 125-item format, the three-hour sitting, the 700-out-of-1000 scaled pass mark, and current eligibility and fees) see the ISSMP certification guide.
ISSMP Training
Module 1: Leadership and Organizational Management
The heaviest domain at 21%. Establishing security's role in culture and governance, aligning strategy with organizational goals, building the policy framework, managing security in contracts, running awareness programs, defining metrics, owning the budget, and applying project management discipline to security programs.
- 1 What the ISSMP is and who it's for 8 min Free preview
- 2 Security's role in organizational culture, vision, and mission 9 min π
- 3 Aligning the security program with organizational governance 9 min π
- 4 Defining and implementing information security strategies 10 min π
- 5 Defining and maintaining the security policy framework 10 min π
- 6 Managing security requirements in contracts and agreements 9 min π
- 7 Managing security awareness and training programs 8 min π
- 8 Defining, measuring, and reporting security metrics 9 min π
- 9 Preparing, obtaining, and managing the security budget 8 min π
- 10 Managing security programs, teams, and cross-functional relationships 9 min π
- 11 Applying product development and project management principles to security 8 min π
Module 2: Systems Lifecycle Management
The management view of the system life cycle: integrating security decision points across every phase, overseeing configuration management, absorbing emerging technologies into the architecture without breaking it, running the vulnerability management program at scale, and enforcing security within change control.
- 1 Systems lifecycle management at the manager level 7 min π
- 2 Integrating security decision points and requirements throughout the life cycle 9 min π
- 3 Overseeing security configuration management (CM) processes 8 min π
- 4 Integrating organization initiatives and emerging technologies into the security architecture 9 min π
- 5 Designing a comprehensive vulnerability management program 9 min π
- 6 Managing security testing: scanning, pen testing, threat analysis 8 min π
- 7 Managing security aspects of change control 8 min π
- 8 MLSecOps: managing AI and ML in the system life cycle 8 min π
Module 3: Risk Management
The second-heaviest domain at 20%. Building and running a risk management program, understanding tolerance and appetite, conducting assessments, treating risk, controlling supply chain and third-party exposure, and using modern frameworks including NIST AI RMF and ISO/IEC 42001.
- 1 Building and managing the risk management program 9 min π
- 2 Risk tolerance, appetite, and organizational asset inventory 8 min π
- 3 Analyzing organizational risk and determining countermeasures 10 min π
- 4 Risk treatment options and cost-benefit analysis 9 min π
- 5 Documenting and managing agreed risks and treatments 8 min π
- 6 Managing security risks within the supply chain 9 min π
- 7 Conducting risk assessments: qualitative and quantitative 8 min π
- 8 Managing risk controls: effectiveness, coverage, monitoring 8 min π
- 9 Risk frameworks: NIST RMF, ISO 31000, FAIR, and how to choose 8 min π
- 10 AI risk management: NIST AI RMF and ISO/IEC 42001 8 min π
Module 4: Security Operations
Standing up and running the security operations center, the threat intelligence program, and the incident management program β with the manager's view of documentation, ownership, tooling choices, and the operational integration of AI as both defense and attack surface.
- 1 Establishing and running a Security Operations Center 9 min π
- 2 SOC documentation: runbooks, playbooks, standard operating procedures 7 min π
- 3 Establishing and maintaining a threat intelligence program 8 min π
- 4 Threat modeling and attack categorization at operational level 7 min π
- 5 Correlating security events and defining actionable alerts 7 min π
- 6 Establishing an incident management program: documentation and case management 9 min π
- 7 Incident response team, methodologies, and handling processes 8 min π
- 8 Investigation processes, quantifying impact, and root cause analysis 8 min π
- 9 AIOps and adversarial AI in security operations 8 min π
Module 5: Contingency Management
The manager's view of business continuity, disaster recovery, and continuity of operations: BIA-driven planning, alternative recovery strategies, plan maintenance and testing, and executing response and recovery through a real disruption.
- 1 Contingency planning fundamentals: BCP, DRP, COOP 9 min π
- 2 Business Impact Analysis and analyzing resiliency factors 8 min π
- 3 Crisis communications, roles, and third-party contingency dependencies 7 min π
- 4 Developing recovery strategies 8 min π
- 5 Maintaining and testing contingency plans 8 min π
- 6 Managing disaster response and recovery execution 8 min π
Module 6: Law, Ethics, and Security Compliance Management
The legal, regulatory, and ethical framework the ISSMP navigates: jurisdictions and trans-border data flow, applicable laws and privacy regimes, intellectual property, the ISC2 Code of Ethics, compliance framework selection and implementation, working with auditors and regulators, and managing compliance exceptions.
- 1 Legal jurisdictions and trans-border data flow 8 min π
- 2 Applicable security and privacy laws and regulations 9 min π
- 3 Intellectual property laws for information security 7 min π
- 4 The ISC2 Code of Ethics and organizational professional ethics 6 min π
- 5 Selecting, implementing, and monitoring compliance frameworks 8 min π
- 6 Coordinating with auditors and regulators 7 min π
- 7 Documenting and managing compliance exceptions and risk waivers 7 min π
Frequently asked questions about the ISSMP training course
Is the ISSMP training course free?
Yes. The course costs nothing to read and opens once you are signed in to a free Certifym account, no payment and no card.
How is the course structured?
One module per official ISSMP exam domain, in ISC2’s published order, with each module weighted to the domain’s published percentage. Leadership and Organizational Management is the largest at 21% and Contingency Management the smallest at 12%, so the modules differ in size the way the exam does.
Does this replace ISC2’s official training?
No. ISC2 publishes the authoritative ISSMP exam outline and sells official training against it. This course is an independent study companion written from the publicly available outline, meant to be read alongside practice questions. It is not an ISC2 product and carries no ISC2 endorsement.
Do I need the CISSP or management experience first?
The ISSMP was originally a CISSP concentration and is now a standalone advanced certification; confirm the current eligibility rules with ISC2 before you plan around them. The course is written for people who already hold management or program responsibility, or are moving into it, it assumes you understand security controls and spends its time on how to govern, fund, and defend them.
What should I do after finishing the course?
Move to the ISSMP practice exam, 125 questions on a three-hour timer weighted to the official domains. Work until you clear roughly 70% in each domain separately, not just on the total, then book with Pearson VUE.
Is the course current with the latest ISSMP outline?
It is built against the outline effective August 1, 2025, the revision that restructured the six domains around today’s management job and embedded AI governance across all of them. ISC2 can revise the outline at any time; download the current one from isc2.org before you schedule.
Trademark notice & independence. Certifym.net is operated by Certifym Exam Services, LLC and is not affiliated with, endorsed by, or sponsored by ISC2, Inc. ISC2®, ISSMP®, CISSP®, and CBK® are registered marks of ISC2, Inc. Certification names and marks are used solely to identify the certification for which these independent study materials are designed. The ISSMP exam outline and its domain structure are the property of ISC2, Inc.; candidates should download the official, current exam outline directly from isc2.org.
All course content, questions, answers, and explanations on Certifym are original content created for study purposes. They are not actual ISC2 training materials or examination questions and are not represented as such. Studying with these materials does not guarantee a passing result on any live certification exam. Exam requirements, format, domain weights, pricing, and eligibility policies are set by ISC2 and may change; always verify current details on isc2.org before scheduling your exam.
