Certification guide
The Information Systems Security Engineering Professional (ISSEP) is ISC2’s credential for the people who build security into systems, the engineers who take an organization’s protection needs and turn them into requirements, architectures, designs, and verified, authorized systems. Where the CISSP proves breadth across the security profession, the ISSEP proves you can practice security as a systems engineering discipline: applying standards like NIST SP 800-160 and ISO/IEC/IEEE 15288, running trade studies, allocating security functions to components, and generating the verification evidence that authorization decisions rest on. It is the signature credential for security engineers in defense, intelligence, and other high-assurance environments, and it carries real weight anywhere resumes cross a contracting officer’s desk. Originally a CISSP concentration, it is now a standalone advanced certification, one of the three highest-bar credentials ISC2 offers.
The exam outline was refreshed effective August 1, 2025, and the update matters: the domains were revised from the latest Job Task Analysis, and AI security engineering now runs through all five, formal validation of ML components, adversarial threat modeling at requirements time, secure training-data pipelines, hardware-rooted protection of model weights, adversarial testing protocols, and drift-triggered retraining and rollback under change control. Study materials aligned to the pre-2025 outline will leave gaps. Eligibility runs two ways: hold the CISSP with two years of cumulative experience in one or more ISSEP domains, or qualify without the CISSP on seven years of cumulative experience in two or more domains.
Systems Security Engineering Foundations
Domain 1 · 24%The heaviest domain covers the discipline itself: trust concepts and hierarchies, how security engineering integrates with the ISO/IEC/IEEE 15288 processes, structural design principles, governance and compliance, and integration with development methodologies including MBSE. It also owns technical management (configuration, information, measurement, and quality assurance processes) plus procurement and supply chain risk management, and resource analysis with Monte Carlo methods, MTBF, MTTR, and Maximum Tolerable Downtime.
Risk Management
Domain 2 · 20%Security risk management aligned with enterprise risk management and integrated across the lifecycle. Expect the full cycle twice over, once for risk to the system and once for risk to operations: establishing context, identifying threats and vulnerabilities, inherent risk analysis, risk evaluation, monitoring changes to posture, and documenting findings and decisions in a form that survives audit and personnel turnover.
Security Planning and Engineering
Domain 3 · 22%The design core: analyzing the organizational and operational environment, capturing stakeholder requirements, and applying system security principles, resiliency and diversity, defense-in-depth and Zero Trust, fail-safe defaults, single points of failure, least privilege, economy of mechanism, and separation of functions. It runs through developing the security requirements baseline, functional analysis and allocation, design traceability, trade-off studies, and design validation, with secure data pipelines and protected model weights for AI components.
Systems Security Implementation, Verification and Validation
Domain 4 · 20%Turning design into fielded, evidenced reality: implementing and integrating security solutions, supporting CI/CD and DevSecOps, developing security test plans, supporting verification, updating the risk analysis as results come in, and documenting stakeholder acceptance. The 2025 outline adds adversarial testing of AI-driven controls and using machine learning to mine test data and logs for the edge cases manual review misses.
Secure Operations, Change Management and Disposal
Domain 5 · 14%The lightest domain closes the lifecycle: secure operations plans with defined roles and event-reporting requirements, continuous monitoring design, incident response support, secure maintenance, change reviews and impact assessment with verification and validation of changes, and disposal, sanitization requirements, decommissioning procedures, audit of the results, and data retention policies. Model drift monitoring and secure model-update delivery now live here too.
Our practice exam mirrors the real thing: 125 questions in 180 minutes, drawn to the official domain weights: 30 questions from Foundations, 25 from Risk Management, 28 from Planning and Engineering, 25 from Implementation and V&V, and 17 from Operations, Change Management and Disposal. We set the pass mark at 70%, the honest raw-score equivalent of ISC2’s 700-out-of-1000 scaled grade, so a pass here means you covered the blueprint, not luck in the heavy ones. Every question is scenario-based with an explanation that tells you why the best answer beats the near misses.
ISC2 ISSEP - Practice Exam
Full-length ISSEP practice exam — 125 questions apportioned to the official August 1, 2025 exam outline weights across all five domains, with scenario-based items and detailed…
Subscribe to startFrequently asked questions about ISSEP
What is the ISSEP certification?
The Information Systems Security Engineering Professional (ISSEP) is ISC2’s credential for engineers who build security into systems, turning an organization’s protection needs into requirements, architectures, designs, and verified, authorized systems. Originally a CISSP concentration, it is now a standalone advanced certification and one of the three highest-bar credentials ISC2 offers.
How many questions are on the ISSEP exam and how long is it?
The exam is 125 questions in 3 hours. Items are multiple choice plus advanced item types, and the exam is delivered at Pearson VUE.
What is the passing score for the ISSEP exam?
700 out of 1000 on ISC2’s scaled scoring system. The scaled score is not a raw percentage, but 70% is the honest raw-score equivalent, which is why the Certifym practice exam sets its pass mark at 70%.
What are the eligibility requirements for the ISSEP?
Eligibility runs two ways. You can hold the CISSP with two years of cumulative experience in one or more ISSEP domains, or you can qualify without the CISSP on seven years of cumulative experience in two or more of the domains.
How hard is the ISSEP exam?
It is one of ISC2’s three highest-bar credentials, and the experience requirements reflect that, either a CISSP plus two years in the domains, or seven years across two or more domains. The exam is a systems engineering discipline test, not a breadth test: expect trade studies, functional analysis and allocation, design traceability, and verification evidence rather than recall.
What domains does the ISSEP cover and how are they weighted?
Five domains: Systems Security Engineering Foundations (24%), Risk Management (20%), Security Planning and Engineering (22%), Systems Security Implementation, Verification and Validation (20%), and Secure Operations, Change Management and Disposal (14%). Foundations and Planning and Engineering are the heaviest and should absorb the most study time.
What changed in the August 1, 2025 exam outline?
The domains were revised from the latest Job Task Analysis, and AI security engineering now runs through all five: formal validation of ML components, adversarial threat modeling at requirements time, secure training-data pipelines, hardware-rooted protection of model weights, adversarial testing protocols, and drift-triggered retraining and rollback under change control. Study materials aligned to the pre-2025 outline will leave gaps.
What standards and frameworks does the ISSEP draw on?
NIST SP 800-160 and ISO/IEC/IEEE 15288 are central, the exam expects you to know how security engineering integrates with the 15288 process set. Alongside those you will see system security principles such as resiliency and diversity, defense-in-depth and Zero Trust, fail-safe defaults, least privilege, economy of mechanism, and separation of functions, plus MBSE, CI/CD and DevSecOps integration, and supply chain risk management.
How do I prepare for the ISSEP exam?
Study against the outline effective August 1, 2025 rather than older material, then drill scenarios under exam conditions. The Certifym practice exam mirrors the real thing: 125 questions in 180 minutes drawn to the official domain weights: 30 from Foundations, 25 from Risk Management, 28 from Planning and Engineering, 25 from Implementation and V&V, and 17 from Operations, Change Management and Disposal, with a 70% pass mark and an explanation on every question that tells you why the best answer beats the near misses.
What is the difference between the ISSEP and the CISSP?
The CISSP proves breadth across the security profession. The ISSEP proves you can practice security as a systems engineering discipline, applying NIST SP 800-160 and ISO/IEC/IEEE 15288, running trade studies, allocating security functions to components, and generating the verification evidence that authorization decisions rest on. The two are also linked by eligibility: holding the CISSP reduces the ISSEP experience requirement to two years in one or more domains.
Trademark notice & independence. Certifym.net is operated by Certifym Exam Services, LLC and is not affiliated with, endorsed by, or sponsored by ISC2, Inc. ISC2®, ISSEP®, CISSP®, and CBK® are registered marks of ISC2, Inc. For official exam registration, policies, and the authoritative exam outline, visit isc2.org.
All practice questions on this site are original content created by Certifym.net to align with the publicly available exam outline. They are not actual exam questions. Practicing with these materials does not guarantee a passing result on any live certification exam.
