ISSEP Training Course

Training course

This is a free, self-paced reading course for ISSEP: Information Systems Security Engineering Professional: ISC2’s credential for the people who build security into systems rather than assess it afterwards. The ISSEP treats security as a systems engineering discipline: you take an organization’s protection needs and turn them into requirements, architectures, designs, and verified, authorized systems, working inside NIST SP 800-160 and ISO/IEC/IEEE 15288, running trade studies, allocating security functions to components, and producing the verification evidence an authorization decision rests on. It is the signature credential for security engineers in defense, intelligence, and other high-assurance environments, and originally a CISSP concentration it now stands alone as one of the three highest-bar credentials ISC2 offers.

The course is organized as one module per official exam domain, in the order ISC2 publishes them, and each module carries the domain’s published weight. It is written against the outline effective August 1, 2025, which is a meaningful distinction rather than a version number: the domains were revised from the latest Job Task Analysis and AI security engineering now runs through all five, formal validation of ML components, adversarial threat modeling at requirements time, secure training-data pipelines, hardware-rooted protection of model weights, adversarial testing protocols, and drift-triggered retraining under change control. Material aligned to the pre-2025 outline leaves gaps in every domain.

ISSEP Expert level 5 modules Domain-weighted Self-paced Free account

What the course covers

Systems Security Engineering Foundations

Module 1 · 24%

The heaviest module covers the discipline itself: trust concepts and hierarchies, how security engineering integrates with the ISO/IEC/IEEE 15288 processes, structural design principles, governance and compliance, and integration with development methodologies including MBSE. Technical management belongs here too (configuration, information, measurement, and quality assurance processes) alongside procurement and supply chain risk management, and resource analysis with Monte Carlo methods, MTBF, MTTR, and Maximum Tolerable Downtime.

Risk Management

Module 2 · 20%

Security risk management aligned with enterprise risk management and integrated across the lifecycle. The module runs the full cycle twice over, once for risk to the system and once for risk to operations: establishing context, identifying threats and vulnerabilities, analyzing inherent risk, evaluating it, monitoring changes in posture, and documenting findings and decisions in a form that survives both an audit and the departure of the person who wrote them.

Security Planning and Engineering

Module 3 · 22%

The design core: analyzing the organizational and operational environment, capturing stakeholder requirements, and applying system security principles, resiliency and diversity, defense-in-depth and Zero Trust, fail-safe defaults, single points of failure, least privilege, economy of mechanism, and separation of functions. From there it works through the security requirements baseline, functional analysis and allocation, design traceability, trade-off studies, and design validation, including secure data pipelines and protected model weights where AI components are in scope.

Systems Security Implementation, Verification and Validation

Module 4 · 20%

Turning a design into fielded, evidenced reality: implementing and integrating security solutions, supporting CI/CD and DevSecOps, developing security test plans, supporting verification activity, updating the risk analysis as results arrive, and documenting stakeholder acceptance. The 2025 material adds adversarial testing of AI-driven controls and the use of machine learning to mine test data and logs for the edge cases manual review misses.

Secure Operations, Change Management and Disposal

Module 5 · 14%

The lightest module closes the lifecycle: secure operations plans with defined roles and event-reporting requirements, continuous monitoring design, incident response support, secure maintenance, change reviews and impact assessment with verification and validation of the changes themselves, and disposal, sanitization requirements, decommissioning procedures, audit of the results, and data retention policies. Model drift monitoring and secure model-update delivery sit here as well.

How to use it

Read the modules in published order. The ISSEP follows the systems lifecycle, so the sequence is the argument: requirements you never wrote properly in module 3 are what you fail to verify in module 4 and cannot safely change in module 5. After each module, take the matching portion of the ISSEP practice exam rather than saving it all for the end. The items are scenario-based, and reading a domain then immediately being asked to make a trade-off inside it is the only reliable way to find out whether you absorbed a process or just its name. The free ISSEP sample shows the question style with no account needed.

Reading the course itself requires a free Certifym account. For eligibility (the CISSP route with two years in the domains, or the seven-year route without it) along with the 125-item format, the three-hour window, and the 700-out-of-1000 scaled pass mark, see the ISSEP certification guide.

← Back

What ISSEP Is

8 min read · Free preview

The engineer, not the analyst

The Information Systems Security Engineering Professional — ISSEP — is one of three concentration credentials that ISC2 layers on top of the CISSP. The other two are ISSAP, which focuses on security architecture, and ISSMP, which focuses on security management. ISSEP is the engineering track. The distinction matters because CISSP is a generalist credential written for the person who understands security across eight domains. ISSEP is written for the person who builds the system with security engineered in from the first requirements meeting through decommissioning.

ISC2 describes an ISSEP as a "security leader who specializes in the practical application of systems engineering principles and processes to develop secure systems." That phrasing is deliberate. The ISSEP is not the security analyst who reviews a design after the fact and files a memo about what the developers should have done differently. The ISSEP is on the systems engineering team, participating in requirements decomposition, trade studies, configuration management, and verification and validation planning — doing all of that work with a security engineer's eye.

Why the credential exists

ISSEP grew out of a partnership between ISC2 and the U.S. National Security Agency in the early 2000s. The federal government needed a way to identify people who could apply the systems security engineering process to national-security systems, and the credential was originally aligned to the NSA's IATF (Information Assurance Technical Framework) and to the NIST family of publications, particularly what has since become NIST SP 800-160 Volume 1, Engineering Trustworthy Secure Systems. That NIST publication remains the single most important reference for ISSEP preparation, even now that the exam outline has been broadened for commercial as well as government use.

The ISSEP is still heavily used by federal contractors, defense integrators, and civilian agencies that develop or acquire large systems under formal engineering programs. But the current outline is written to be neutral about sector — the same principles apply to any organization that builds a system complex enough to have a documented lifecycle, a stakeholder register, and traceable requirements.

The five domains

The August 1, 2025 exam outline organizes the ISSEP body of knowledge into five domains. The weights tell you where to spend your study time:

  • Domain 1 — Systems Security Engineering Foundations (24%). Trust concepts, structural design principles, integration with the system development methodology, technical management, procurement, and resource analysis. The largest domain.
  • Domain 2 — Risk Management (20%). Applying risk management principles, and doing it twice: once for risk to the system and once for risk to operations, with the same six-step pattern each time.
  • Domain 3 — Security Planning and Engineering (22%). Analyzing the environment, applying system security principles, developing system requirements, and creating the system security design.
  • Domain 4 — Systems Security Implementation, Verification, and Validation (20%). Actually building and integrating security into the system, then verifying that it works.
  • Domain 5 — Secure Operations, Change Management, and Disposal (14%). The rest of the lifecycle after acceptance: monitoring, incident response support, secure change control, and disposal.

What the exam looks like

ISSEP is a 125-item exam with a three-hour time limit. It is available in English only, delivered at Pearson VUE test centers, and the passing score is 700 out of 1000 on ISC2's scaled scoring. Item formats are multiple choice and "advanced item types" — usually drag-and-drop ordering and hotspot selections. Scenario prompts are common: you will read a paragraph describing a program situation and be asked what the ISSEP does next. The correct answer is often the most disciplined engineering step, not the most technically clever fix.

Prerequisites and experience

ISSEP is a concentration, not a standalone credential. The base requirement is a CISSP in good standing plus two years of cumulative full-time experience in one or more of the ISSEP domains. There is an alternative path for candidates without CISSP — seven years of experience in two or more ISSEP domains — but in practice almost everyone comes in through CISSP.

The good news is that if you passed CISSP, you already have most of the vocabulary. The trap is that ISSEP asks you to apply that vocabulary through the systems engineering lifecycle rather than as isolated security controls. The exam favors candidates who can talk about requirements traceability, configuration management, and trade studies as fluently as they talk about defense in depth.

How this course is organized

This training course follows the exam outline domain by domain. Each module is one domain, and the lesson count in each module roughly matches the domain weight. Module 1 (this one) has twelve lessons because the Foundations domain is the largest at 24%. Modules 2 and 4 have ten lessons each; Module 3 has eleven; Module 5 has seven. Every lesson closes with a short key-terms list and further-reading pointers so you can build a personal reference sheet as you go.

Pair this course with the Certifym ISSEP practice exam bank when you are ready to test yourself against full-length practice sets.

Frequently asked questions about the ISSEP training course

Is the ISSEP training course free?

Yes. The course costs nothing to read and opens once you are signed in to a free Certifym account, no payment and no card.

How is the course structured?

One module per official ISSEP exam domain, in ISC2’s published order, with each module weighted to the domain’s published percentage. Because the domains follow the systems lifecycle from foundations through disposal, the order is also the order the work happens in.

Does this replace ISC2’s official training?

No. ISC2 publishes the authoritative ISSEP exam outline and sells official training against it. This course is an independent study companion written from the publicly available outline, meant to be read alongside practice questions. It is not an ISC2 product and carries no ISC2 endorsement.

Do I need the CISSP before starting?

Not to read the course. To hold the credential, ISC2 requires either an active CISSP plus two years of cumulative experience in one or more ISSEP domains, or seven years of cumulative experience in two or more domains without the CISSP. The course assumes you already work in systems or security engineering; it does not teach systems engineering from scratch.

What should I do after finishing the course?

Move to the ISSEP practice exam, which runs 125 scenario questions in 180 minutes at the official domain weights. Work until you clear roughly 70% in each domain separately rather than on the total, then confirm your eligibility route with ISC2 before booking with Pearson VUE.

Is the course current with the latest ISSEP outline?

It is built against the outline effective August 1, 2025, the revision that reworked the domains from the latest Job Task Analysis and threaded AI security engineering through all five of them. ISC2 can revise the outline at any time; download the current one from isc2.org before you schedule.

Trademark notice & independence. Certifym.net is operated by Certifym Exam Services, LLC and is not affiliated with, endorsed by, or sponsored by ISC2, Inc. ISC2®, ISSEP®, CISSP®, and CBK® are registered marks of ISC2, Inc. Certification names and marks are used solely to identify the certification for which these independent study materials are designed. The ISSEP exam outline and its domain structure are the property of ISC2, Inc.; for official exam registration, policies, and the authoritative exam outline, visit isc2.org.

All course content, questions, answers, and explanations on Certifym are original content created for study purposes to align with the publicly available exam outline. They are not actual ISC2 training materials or examination questions and are not represented as such. Studying with these materials does not guarantee a passing result on any live certification exam. Exam requirements, format, domain weights, pricing, and eligibility policies are set by ISC2 and may change; always verify current details on isc2.org before scheduling your exam.