ISC2 ISSMP Training Course

Training course

This is a free, self-paced reading course for ISSMP: Information Systems Security Management Professional: ISC2’s credential for the people who run security programs rather than build or operate the controls inside them. The ISSMP is about setting strategy, winning budgets, governing risk, directing security operations, keeping the business running through a disaster, and answering to regulators and boards. Where the CISSP proves breadth across the profession, the ISSMP proves you can lead it: aligning the program with the organization’s mission, making risk decisions defensible, and translating threats into the language of business impact. Originally a CISSP concentration, it now stands alone as one of the three highest-bar credentials ISC2 offers.

The course is organized as one module per official exam domain, in the order ISC2 publishes them, and each module carries the domain’s published weight. It follows the outline effective August 1, 2025, in which ISC2 restructured the domains around the management job as it exists now and embedded AI governance throughout, shadow AI policy, ethical governance models, the NIST AI RMF and ISO/IEC 42001, MLSecOps decision gates, prompt injection and data poisoning response, model artifacts as continuity dependencies, and the EU AI Act’s risk tiers. Read it expecting judgment questions rather than definitions: on this exam several options are usually defensible and only one is most correct.

ISSMP Expert level 6 modules Domain-weighted Self-paced Free account

What the course covers

Leadership and Organizational Management

Module 1 · 21%

The heaviest module and the heart of the credential: establishing security’s role in culture, vision, and mission; navigating governance and the boundaries of your authority; building the policy framework of policies, standards, baselines, and guidelines; managing contracts, managed services, and the security consequences of mergers; running awareness programs that actually change behavior; defining KPIs and KRIs; preparing and defending a budget; and applying project management principles, including embedding security into agile delivery and governing the organization’s use of AI.

Systems Lifecycle Management

Module 2 · 15%

Integrating security throughout the system life cycle rather than bolting it on: phase-gate governance, configuration management oversight, and folding new initiatives and emerging technology into the security architecture. The vulnerability management program lives here (asset-criticality-driven prioritization, penetration test governance, remediation and compensating controls) along with the security side of change control, from impact analysis to continuous compliance monitoring, extending to MLSecOps gates and treating model weight updates as formal system changes.

Risk Management

Module 3 · 20%

The second-heaviest module: building and running the risk program, appetite and tolerance, asset inventory, qualitative and quantitative assessment with SLE, ARO, and ALE, treatment options and cost-benefit analysis, the risk register, and the question of who is actually entitled to accept a risk. Supply chain risk gets deep treatment through vendor tiering, independent attestation, fourth-party flow-downs, and continuous monitoring, joined by the NIST AI RMF, ISO/IEC 42001, generative AI procurement terms, and model weights as crown-jewel assets.

Security Operations

Module 4 · 18%

Governing the operational machine: SOC charters and documentation, threat intelligence programs built on priority intelligence requirements, baselining and anomaly detection, event correlation, and engineering alerts someone will actually act on. Incident management carries equal weight, the policy-plan-playbook hierarchy, case management and chain of custody, team models, contain-first methodology, impact quantification for executives, and root cause analysis, plus prompt injection and data poisoning response, AIOps guardrails, and ML engineers as formal incident stakeholders.

Contingency Management

Module 5 · 12%

Resilience from analysis through return to normal: the business impact analysis as foundation; the distinctions between COOP, BCP, and DRP; crisis communications and declaration authority; third-party and cloud dependencies; succession planning; recovery strategy selection against RTO and RPO, including the RTO + WRT ≤ MTD arithmetic; the test-type ladder from tabletop to full interruption; plan maintenance triggers; and disciplined disaster response and recovery, now with model artifacts and retraining time counted as continuity considerations.

Law, Ethics, and Security Compliance Management

Module 6 · 14%

The manager as the organization’s legal and ethical conscience: mapping jurisdictions and trans-border data flows, breach notification duties, intellectual property protection for security-relevant assets including trade secrecy for model weights, and the ISC2 Code of Ethics with its ordered canons. Compliance management covers framework selection and implementation, compliance metrics, audit coordination from planning through remediation validation, and governed exception and risk waiver processes, with the EU AI Act and automated decision-making rights now in scope.

How to use it

Read the modules in order, but budget your time by weight: Leadership and Organizational Management and Risk Management together account for 41% of the exam, and they are also where the judgment questions are hardest for people who came up through technical roles. After each module, take the matching portion of the ISSMP practice exam rather than saving it for the end. The items are written at management level, so the useful signal is not whether you recognized the topic but whether you picked the option an accountable security executive would defend. The free ISSMP sample shows that question style with no account needed.

Reading the course itself requires a free Certifym account. For exam logistics (the 125-item format, the three-hour sitting, the 700-out-of-1000 scaled pass mark, and current eligibility and fees) see the ISSMP certification guide.

ISSMP Training

Module 1: Leadership and Organizational Management

The heaviest domain at 21%. Establishing security's role in culture and governance, aligning strategy with organizational goals, building the policy framework, managing security in contracts, running awareness programs, defining metrics, owning the budget, and applying project management discipline to security programs.

  • 1 What the ISSMP is and who it's for 8 min Free preview
  • 2 Security's role in organizational culture, vision, and mission 9 min πŸ”’
  • 3 Aligning the security program with organizational governance 9 min πŸ”’
  • 4 Defining and implementing information security strategies 10 min πŸ”’
  • 5 Defining and maintaining the security policy framework 10 min πŸ”’
  • 6 Managing security requirements in contracts and agreements 9 min πŸ”’
  • 7 Managing security awareness and training programs 8 min πŸ”’
  • 8 Defining, measuring, and reporting security metrics 9 min πŸ”’
  • 9 Preparing, obtaining, and managing the security budget 8 min πŸ”’
  • 10 Managing security programs, teams, and cross-functional relationships 9 min πŸ”’
  • 11 Applying product development and project management principles to security 8 min πŸ”’

Module 2: Systems Lifecycle Management

The management view of the system life cycle: integrating security decision points across every phase, overseeing configuration management, absorbing emerging technologies into the architecture without breaking it, running the vulnerability management program at scale, and enforcing security within change control.

  • 1 Systems lifecycle management at the manager level 7 min πŸ”’
  • 2 Integrating security decision points and requirements throughout the life cycle 9 min πŸ”’
  • 3 Overseeing security configuration management (CM) processes 8 min πŸ”’
  • 4 Integrating organization initiatives and emerging technologies into the security architecture 9 min πŸ”’
  • 5 Designing a comprehensive vulnerability management program 9 min πŸ”’
  • 6 Managing security testing: scanning, pen testing, threat analysis 8 min πŸ”’
  • 7 Managing security aspects of change control 8 min πŸ”’
  • 8 MLSecOps: managing AI and ML in the system life cycle 8 min πŸ”’

Module 3: Risk Management

The second-heaviest domain at 20%. Building and running a risk management program, understanding tolerance and appetite, conducting assessments, treating risk, controlling supply chain and third-party exposure, and using modern frameworks including NIST AI RMF and ISO/IEC 42001.

  • 1 Building and managing the risk management program 9 min πŸ”’
  • 2 Risk tolerance, appetite, and organizational asset inventory 8 min πŸ”’
  • 3 Analyzing organizational risk and determining countermeasures 10 min πŸ”’
  • 4 Risk treatment options and cost-benefit analysis 9 min πŸ”’
  • 5 Documenting and managing agreed risks and treatments 8 min πŸ”’
  • 6 Managing security risks within the supply chain 9 min πŸ”’
  • 7 Conducting risk assessments: qualitative and quantitative 8 min πŸ”’
  • 8 Managing risk controls: effectiveness, coverage, monitoring 8 min πŸ”’
  • 9 Risk frameworks: NIST RMF, ISO 31000, FAIR, and how to choose 8 min πŸ”’
  • 10 AI risk management: NIST AI RMF and ISO/IEC 42001 8 min πŸ”’

Module 4: Security Operations

Standing up and running the security operations center, the threat intelligence program, and the incident management program β€” with the manager's view of documentation, ownership, tooling choices, and the operational integration of AI as both defense and attack surface.

  • 1 Establishing and running a Security Operations Center 9 min πŸ”’
  • 2 SOC documentation: runbooks, playbooks, standard operating procedures 7 min πŸ”’
  • 3 Establishing and maintaining a threat intelligence program 8 min πŸ”’
  • 4 Threat modeling and attack categorization at operational level 7 min πŸ”’
  • 5 Correlating security events and defining actionable alerts 7 min πŸ”’
  • 6 Establishing an incident management program: documentation and case management 9 min πŸ”’
  • 7 Incident response team, methodologies, and handling processes 8 min πŸ”’
  • 8 Investigation processes, quantifying impact, and root cause analysis 8 min πŸ”’
  • 9 AIOps and adversarial AI in security operations 8 min πŸ”’

Module 5: Contingency Management

The manager's view of business continuity, disaster recovery, and continuity of operations: BIA-driven planning, alternative recovery strategies, plan maintenance and testing, and executing response and recovery through a real disruption.

  • 1 Contingency planning fundamentals: BCP, DRP, COOP 9 min πŸ”’
  • 2 Business Impact Analysis and analyzing resiliency factors 8 min πŸ”’
  • 3 Crisis communications, roles, and third-party contingency dependencies 7 min πŸ”’
  • 4 Developing recovery strategies 8 min πŸ”’
  • 5 Maintaining and testing contingency plans 8 min πŸ”’
  • 6 Managing disaster response and recovery execution 8 min πŸ”’

Module 6: Law, Ethics, and Security Compliance Management

The legal, regulatory, and ethical framework the ISSMP navigates: jurisdictions and trans-border data flow, applicable laws and privacy regimes, intellectual property, the ISC2 Code of Ethics, compliance framework selection and implementation, working with auditors and regulators, and managing compliance exceptions.

  • 1 Legal jurisdictions and trans-border data flow 8 min πŸ”’
  • 2 Applicable security and privacy laws and regulations 9 min πŸ”’
  • 3 Intellectual property laws for information security 7 min πŸ”’
  • 4 The ISC2 Code of Ethics and organizational professional ethics 6 min πŸ”’
  • 5 Selecting, implementing, and monitoring compliance frameworks 8 min πŸ”’
  • 6 Coordinating with auditors and regulators 7 min πŸ”’
  • 7 Documenting and managing compliance exceptions and risk waivers 7 min πŸ”’

Frequently asked questions about the ISSMP training course

Is the ISSMP training course free?

Yes. The course costs nothing to read and opens once you are signed in to a free Certifym account, no payment and no card.

How is the course structured?

One module per official ISSMP exam domain, in ISC2’s published order, with each module weighted to the domain’s published percentage. Leadership and Organizational Management is the largest at 21% and Contingency Management the smallest at 12%, so the modules differ in size the way the exam does.

Does this replace ISC2’s official training?

No. ISC2 publishes the authoritative ISSMP exam outline and sells official training against it. This course is an independent study companion written from the publicly available outline, meant to be read alongside practice questions. It is not an ISC2 product and carries no ISC2 endorsement.

Do I need the CISSP or management experience first?

The ISSMP was originally a CISSP concentration and is now a standalone advanced certification; confirm the current eligibility rules with ISC2 before you plan around them. The course is written for people who already hold management or program responsibility, or are moving into it, it assumes you understand security controls and spends its time on how to govern, fund, and defend them.

What should I do after finishing the course?

Move to the ISSMP practice exam, 125 questions on a three-hour timer weighted to the official domains. Work until you clear roughly 70% in each domain separately, not just on the total, then book with Pearson VUE.

Is the course current with the latest ISSMP outline?

It is built against the outline effective August 1, 2025, the revision that restructured the six domains around today’s management job and embedded AI governance across all of them. ISC2 can revise the outline at any time; download the current one from isc2.org before you schedule.

Trademark notice & independence. Certifym.net is operated by Certifym Exam Services, LLC and is not affiliated with, endorsed by, or sponsored by ISC2, Inc. ISC2®, ISSMP®, CISSP®, and CBK® are registered marks of ISC2, Inc. Certification names and marks are used solely to identify the certification for which these independent study materials are designed. The ISSMP exam outline and its domain structure are the property of ISC2, Inc.; candidates should download the official, current exam outline directly from isc2.org.

All course content, questions, answers, and explanations on Certifym are original content created for study purposes. They are not actual ISC2 training materials or examination questions and are not represented as such. Studying with these materials does not guarantee a passing result on any live certification exam. Exam requirements, format, domain weights, pricing, and eligibility policies are set by ISC2 and may change; always verify current details on isc2.org before scheduling your exam.