Training course
This is a free, self-paced reading course for ISSEP: Information Systems Security Engineering Professional: ISC2’s credential for the people who build security into systems rather than assess it afterwards. The ISSEP treats security as a systems engineering discipline: you take an organization’s protection needs and turn them into requirements, architectures, designs, and verified, authorized systems, working inside NIST SP 800-160 and ISO/IEC/IEEE 15288, running trade studies, allocating security functions to components, and producing the verification evidence an authorization decision rests on. It is the signature credential for security engineers in defense, intelligence, and other high-assurance environments, and originally a CISSP concentration it now stands alone as one of the three highest-bar credentials ISC2 offers.
The course is organized as one module per official exam domain, in the order ISC2 publishes them, and each module carries the domain’s published weight. It is written against the outline effective August 1, 2025, which is a meaningful distinction rather than a version number: the domains were revised from the latest Job Task Analysis and AI security engineering now runs through all five, formal validation of ML components, adversarial threat modeling at requirements time, secure training-data pipelines, hardware-rooted protection of model weights, adversarial testing protocols, and drift-triggered retraining under change control. Material aligned to the pre-2025 outline leaves gaps in every domain.
What the course covers
Systems Security Engineering Foundations
Module 1 · 24%The heaviest module covers the discipline itself: trust concepts and hierarchies, how security engineering integrates with the ISO/IEC/IEEE 15288 processes, structural design principles, governance and compliance, and integration with development methodologies including MBSE. Technical management belongs here too (configuration, information, measurement, and quality assurance processes) alongside procurement and supply chain risk management, and resource analysis with Monte Carlo methods, MTBF, MTTR, and Maximum Tolerable Downtime.
Risk Management
Module 2 · 20%Security risk management aligned with enterprise risk management and integrated across the lifecycle. The module runs the full cycle twice over, once for risk to the system and once for risk to operations: establishing context, identifying threats and vulnerabilities, analyzing inherent risk, evaluating it, monitoring changes in posture, and documenting findings and decisions in a form that survives both an audit and the departure of the person who wrote them.
Security Planning and Engineering
Module 3 · 22%The design core: analyzing the organizational and operational environment, capturing stakeholder requirements, and applying system security principles, resiliency and diversity, defense-in-depth and Zero Trust, fail-safe defaults, single points of failure, least privilege, economy of mechanism, and separation of functions. From there it works through the security requirements baseline, functional analysis and allocation, design traceability, trade-off studies, and design validation, including secure data pipelines and protected model weights where AI components are in scope.
Systems Security Implementation, Verification and Validation
Module 4 · 20%Turning a design into fielded, evidenced reality: implementing and integrating security solutions, supporting CI/CD and DevSecOps, developing security test plans, supporting verification activity, updating the risk analysis as results arrive, and documenting stakeholder acceptance. The 2025 material adds adversarial testing of AI-driven controls and the use of machine learning to mine test data and logs for the edge cases manual review misses.
Secure Operations, Change Management and Disposal
Module 5 · 14%The lightest module closes the lifecycle: secure operations plans with defined roles and event-reporting requirements, continuous monitoring design, incident response support, secure maintenance, change reviews and impact assessment with verification and validation of the changes themselves, and disposal, sanitization requirements, decommissioning procedures, audit of the results, and data retention policies. Model drift monitoring and secure model-update delivery sit here as well.
How to use it
Read the modules in published order. The ISSEP follows the systems lifecycle, so the sequence is the argument: requirements you never wrote properly in module 3 are what you fail to verify in module 4 and cannot safely change in module 5. After each module, take the matching portion of the ISSEP practice exam rather than saving it all for the end. The items are scenario-based, and reading a domain then immediately being asked to make a trade-off inside it is the only reliable way to find out whether you absorbed a process or just its name. The free ISSEP sample shows the question style with no account needed.
Reading the course itself requires a free Certifym account. For eligibility (the CISSP route with two years in the domains, or the seven-year route without it) along with the 125-item format, the three-hour window, and the 700-out-of-1000 scaled pass mark, see the ISSEP certification guide.
ISSEP Training
Module 1: Systems Security Engineering Foundations
Ground floor for the ISSEP: how systems security engineering relates to systems engineering as a whole, the trust concepts and structural design principles the exam expects you to work from, and the technical management activities β configuration management, information management, measurement, quality assurance, procurement, and resource analysis β that keep security work aligned with the wider program.
- 1 What ISSEP Is 8 min Free preview
- 2 Systems Security Engineering Fundamentals and Trust 10 min π
- 3 Structural Design Principles: NIST and ISO Frameworks 10 min π
- 4 Executing SSE Processes: Hardware, Software, Data 10 min π
- 5 Organizational Security Authorities and Governance 9 min π
- 6 Design Concepts: Open, Proprietary, Modular 8 min π
- 7 Integrating Security into the SDLC 10 min π
- 8 Assurance Methods and Lifecycle Models 9 min π
- 9 Technical Management: CM, Information Management, Measurement, QA 10 min π
- 10 Technology Procurement Management and Supply Chain Risk 9 min π
- 11 Resource Analysis and Cost Estimation 9 min π
- 12 Reliability Metrics: MTBF, MTTF, MTTR, MTD 8 min π
Module 2: Risk Management
The ISSEP's risk management responsibility runs twice through the same six-step loop: once for risk to the system itself and once for risk to operations. This module walks through the principles, the loop, and the documentation that keeps risk posture visible to leadership.
- 1 Security Risk Management Principles 10 min π
- 2 Aligning Security Risk with Enterprise Risk Management 9 min π
- 3 Risk Management Integration Across the Lifecycle 9 min π
- 4 Establishing Risk Context 8 min π
- 5 Identifying System Security Risks 10 min π
- 6 Performing Inherent Risk Analysis 9 min π
- 7 Risk Evaluation and Treatment Decisions 9 min π
- 8 Monitoring Changes to Risk Posture 8 min π
- 9 Documenting Risk Posture: Findings and Decisions 8 min π
- 10 Managing Risk to Operations 9 min π
Module 3: Security Planning and Engineering
Where the ISSEP does the most engineering. Analyzing the organizational and operational environment, applying system security principles from resiliency through least privilege, developing the security requirements baseline, and creating a system security design that survives trade studies.
- 1 Analyzing the Organizational and Operational Environment 9 min π
- 2 Capturing Stakeholder Requirements 9 min π
- 3 Roles, Responsibilities, Constraints, and Assumptions 8 min π
- 4 Preparing the Security Validation Plan 8 min π
- 5 Resiliency and Layered Security 10 min π
- 6 Fail-Safe Defaults and Single Points of Failure 8 min π
- 7 Least Privilege, Economy of Mechanism, and Separation 9 min π
- 8 Automation, SecDevOps, and Software Assurance 9 min π
- 9 Developing System Requirements and Security Context 9 min π
- 10 Documenting the Security Requirements Baseline 8 min π
- 11 Creating the System Security Design and Trade-off Studies 10 min π
Module 4: Systems Security Implementation, Verification, and Validation
Where designs become working systems and working systems are proven to satisfy the requirements they were built for. Implementation and integration, CI/CD and DevSecOps discipline, security test planning and execution, and the stakeholder acceptance record.
- 1 Implementing Security Solutions 9 min π
- 2 Integrating Security into the System 8 min π
- 3 Continuous Integration and Continuous Delivery 9 min π
- 4 DevSecOps in the Engineering Lifecycle 8 min π
- 5 Developing Security Test Plans 8 min π
- 6 Supporting System Security Verification 8 min π
- 7 Verification vs Validation Methods 8 min π
- 8 Reviewing and Updating Risk Analysis Post-Implementation 8 min π
- 9 Documenting Stakeholder Acceptance 7 min π
- 10 Testing AI and Emerging Technology Components 8 min π
Module 5: Secure Operations, Change Management, and Disposal
The operational life of the system, from initial secure operations planning through continuous monitoring, incident response, change management under sustained operation, and eventually secure disposal at end of life.
- 1 Developing the Secure Operations Plan 8 min π
- 2 Security Event Reporting Requirements 7 min π
- 3 Continuous Monitoring Design 8 min π
- 4 Supporting the Incident Response Process 8 min π
- 5 Secure Maintenance and Change Reviews 8 min π
- 6 Change Impact Assessment and Verification 7 min π
- 7 Secure Disposal, Decommissioning, and Data Retention 8 min π
Frequently asked questions about the ISSEP training course
Is the ISSEP training course free?
Yes. The course costs nothing to read and opens once you are signed in to a free Certifym account, no payment and no card.
How is the course structured?
One module per official ISSEP exam domain, in ISC2’s published order, with each module weighted to the domain’s published percentage. Because the domains follow the systems lifecycle from foundations through disposal, the order is also the order the work happens in.
Does this replace ISC2’s official training?
No. ISC2 publishes the authoritative ISSEP exam outline and sells official training against it. This course is an independent study companion written from the publicly available outline, meant to be read alongside practice questions. It is not an ISC2 product and carries no ISC2 endorsement.
Do I need the CISSP before starting?
Not to read the course. To hold the credential, ISC2 requires either an active CISSP plus two years of cumulative experience in one or more ISSEP domains, or seven years of cumulative experience in two or more domains without the CISSP. The course assumes you already work in systems or security engineering; it does not teach systems engineering from scratch.
What should I do after finishing the course?
Move to the ISSEP practice exam, which runs 125 scenario questions in 180 minutes at the official domain weights. Work until you clear roughly 70% in each domain separately rather than on the total, then confirm your eligibility route with ISC2 before booking with Pearson VUE.
Is the course current with the latest ISSEP outline?
It is built against the outline effective August 1, 2025, the revision that reworked the domains from the latest Job Task Analysis and threaded AI security engineering through all five of them. ISC2 can revise the outline at any time; download the current one from isc2.org before you schedule.
Trademark notice & independence. Certifym.net is operated by Certifym Exam Services, LLC and is not affiliated with, endorsed by, or sponsored by ISC2, Inc. ISC2®, ISSEP®, CISSP®, and CBK® are registered marks of ISC2, Inc. Certification names and marks are used solely to identify the certification for which these independent study materials are designed. The ISSEP exam outline and its domain structure are the property of ISC2, Inc.; for official exam registration, policies, and the authoritative exam outline, visit isc2.org.
All course content, questions, answers, and explanations on Certifym are original content created for study purposes to align with the publicly available exam outline. They are not actual ISC2 training materials or examination questions and are not represented as such. Studying with these materials does not guarantee a passing result on any live certification exam. Exam requirements, format, domain weights, pricing, and eligibility policies are set by ISC2 and may change; always verify current details on isc2.org before scheduling your exam.
