Training course
This is a free, self-paced reading course for ISSMP: Information Systems Security Management Professional: ISC2’s credential for the people who run security programs rather than build or operate the controls inside them. The ISSMP is about setting strategy, winning budgets, governing risk, directing security operations, keeping the business running through a disaster, and answering to regulators and boards. Where the CISSP proves breadth across the profession, the ISSMP proves you can lead it: aligning the program with the organization’s mission, making risk decisions defensible, and translating threats into the language of business impact. Originally a CISSP concentration, it now stands alone as one of the three highest-bar credentials ISC2 offers.
The course is organized as one module per official exam domain, in the order ISC2 publishes them, and each module carries the domain’s published weight. It follows the outline effective August 1, 2025, in which ISC2 restructured the domains around the management job as it exists now and embedded AI governance throughout, shadow AI policy, ethical governance models, the NIST AI RMF and ISO/IEC 42001, MLSecOps decision gates, prompt injection and data poisoning response, model artifacts as continuity dependencies, and the EU AI Act’s risk tiers. Read it expecting judgment questions rather than definitions: on this exam several options are usually defensible and only one is most correct.
What the course covers
Leadership and Organizational Management
Module 1 · 21%The heaviest module and the heart of the credential: establishing security’s role in culture, vision, and mission; navigating governance and the boundaries of your authority; building the policy framework of policies, standards, baselines, and guidelines; managing contracts, managed services, and the security consequences of mergers; running awareness programs that actually change behavior; defining KPIs and KRIs; preparing and defending a budget; and applying project management principles, including embedding security into agile delivery and governing the organization’s use of AI.
Systems Lifecycle Management
Module 2 · 15%Integrating security throughout the system life cycle rather than bolting it on: phase-gate governance, configuration management oversight, and folding new initiatives and emerging technology into the security architecture. The vulnerability management program lives here (asset-criticality-driven prioritization, penetration test governance, remediation and compensating controls) along with the security side of change control, from impact analysis to continuous compliance monitoring, extending to MLSecOps gates and treating model weight updates as formal system changes.
Risk Management
Module 3 · 20%The second-heaviest module: building and running the risk program, appetite and tolerance, asset inventory, qualitative and quantitative assessment with SLE, ARO, and ALE, treatment options and cost-benefit analysis, the risk register, and the question of who is actually entitled to accept a risk. Supply chain risk gets deep treatment through vendor tiering, independent attestation, fourth-party flow-downs, and continuous monitoring, joined by the NIST AI RMF, ISO/IEC 42001, generative AI procurement terms, and model weights as crown-jewel assets.
Security Operations
Module 4 · 18%Governing the operational machine: SOC charters and documentation, threat intelligence programs built on priority intelligence requirements, baselining and anomaly detection, event correlation, and engineering alerts someone will actually act on. Incident management carries equal weight, the policy-plan-playbook hierarchy, case management and chain of custody, team models, contain-first methodology, impact quantification for executives, and root cause analysis, plus prompt injection and data poisoning response, AIOps guardrails, and ML engineers as formal incident stakeholders.
Contingency Management
Module 5 · 12%Resilience from analysis through return to normal: the business impact analysis as foundation; the distinctions between COOP, BCP, and DRP; crisis communications and declaration authority; third-party and cloud dependencies; succession planning; recovery strategy selection against RTO and RPO, including the RTO + WRT ≤ MTD arithmetic; the test-type ladder from tabletop to full interruption; plan maintenance triggers; and disciplined disaster response and recovery, now with model artifacts and retraining time counted as continuity considerations.
Law, Ethics, and Security Compliance Management
Module 6 · 14%The manager as the organization’s legal and ethical conscience: mapping jurisdictions and trans-border data flows, breach notification duties, intellectual property protection for security-relevant assets including trade secrecy for model weights, and the ISC2 Code of Ethics with its ordered canons. Compliance management covers framework selection and implementation, compliance metrics, audit coordination from planning through remediation validation, and governed exception and risk waiver processes, with the EU AI Act and automated decision-making rights now in scope.
How to use it
Read the modules in order, but budget your time by weight: Leadership and Organizational Management and Risk Management together account for 41% of the exam, and they are also where the judgment questions are hardest for people who came up through technical roles. After each module, take the matching portion of the ISSMP practice exam rather than saving it for the end. The items are written at management level, so the useful signal is not whether you recognized the topic but whether you picked the option an accountable security executive would defend. The free ISSMP sample shows that question style with no account needed.
Reading the course itself requires a free Certifym account. For exam logistics (the 125-item format, the three-hour sitting, the 700-out-of-1000 scaled pass mark, and current eligibility and fees) see the ISSMP certification guide.
What the ISSMP is and who it's for
The credential in one sentence
The Information Systems Security Management Professional (ISSMP) is an ISC2 advanced certification for security leaders who establish, present, and govern information security programs. Where the CISSP tests the breadth of the security practitioner's body of knowledge, the ISSMP concentrates on the management, leadership, and governance layer that sits on top of it.
Position in the ISC2 family
The ISSMP is one of three ISC2 advanced concentrations. The other two — the ISSAP (architecture) and the ISSEP (engineering) — cover the same body of knowledge but from different vantage points. All three were formerly styled with a "CISSP-" prefix (e.g., CISSP-ISSMP). ISC2 dropped the prefix and, as of October 2023, removed the hard CISSP prerequisite. You can now qualify for the ISSMP by holding the CISSP plus two years of ISSMP-domain experience, or by having seven cumulative years of full-time experience in two or more ISSMP domains without holding the CISSP.
The six-domain outline (effective August 1, 2025)
ISC2 refreshed the ISSMP outline through a Job Task Analysis (JTA) and released the current version on August 1, 2025. The six domains and their average weights are:
- Leadership and Organizational Management — 21%
- Systems Lifecycle Management — 15%
- Risk Management — 20%
- Security Operations — 18%
- Contingency Management — 12%
- Law, Ethics, and Security Compliance Management — 14%
The updated outline weaves AI security throughout — MLSecOps, AIOps, adversarial AI, model drift as a continuity risk, and legal frameworks like the EU AI Act and NIST AI RMF now appear as subtopics inside the traditional domains rather than as a separate track.
Exam mechanics
The ISSMP is a three-hour, 125-item exam delivered at Pearson VUE (in person or online-proctored). Items are multiple choice plus advanced item types (drag-and-drop, scenario-based). The passing grade is 700 out of 1000 on a scaled score. English is the only supported language. Unlike the CISSP, the ISSMP is not currently adaptive — you sit the full item bank.
What the certification is actually testing
Every question on this exam is written from the perspective of the person accountable for the security program, not the person configuring the firewall. When a scenario says "the CISO discovers…" or "the security manager is asked to…," the correct answer is almost always the one that treats security as a business function: aligned to organizational strategy, funded through a defensible budget process, measured with metrics that mean something to the board, and defensible under legal scrutiny. Candidates who fail the ISSMP typically fail because they answer as a senior engineer would — reaching for the technically strongest control instead of the option that best fits governance, communication, or business alignment.
How to use this course
The 51 lessons here are organized to match the six domains and their weights. Domain 1 (this module) has 11 lessons because it is the heaviest of the six. Every lesson closes with key terms and further reading. Once you finish the course, the ISSMP practice exam bank drills the same material with scenario-format questions modeled on the actual exam.
Frequently asked questions about the ISSMP training course
Is the ISSMP training course free?
Yes. The course costs nothing to read and opens once you are signed in to a free Certifym account, no payment and no card.
How is the course structured?
One module per official ISSMP exam domain, in ISC2’s published order, with each module weighted to the domain’s published percentage. Leadership and Organizational Management is the largest at 21% and Contingency Management the smallest at 12%, so the modules differ in size the way the exam does.
Does this replace ISC2’s official training?
No. ISC2 publishes the authoritative ISSMP exam outline and sells official training against it. This course is an independent study companion written from the publicly available outline, meant to be read alongside practice questions. It is not an ISC2 product and carries no ISC2 endorsement.
Do I need the CISSP or management experience first?
The ISSMP was originally a CISSP concentration and is now a standalone advanced certification; confirm the current eligibility rules with ISC2 before you plan around them. The course is written for people who already hold management or program responsibility, or are moving into it, it assumes you understand security controls and spends its time on how to govern, fund, and defend them.
What should I do after finishing the course?
Move to the ISSMP practice exam, 125 questions on a three-hour timer weighted to the official domains. Work until you clear roughly 70% in each domain separately, not just on the total, then book with Pearson VUE.
Is the course current with the latest ISSMP outline?
It is built against the outline effective August 1, 2025, the revision that restructured the six domains around today’s management job and embedded AI governance across all of them. ISC2 can revise the outline at any time; download the current one from isc2.org before you schedule.
Trademark notice & independence. Certifym.net is operated by Certifym Exam Services, LLC and is not affiliated with, endorsed by, or sponsored by ISC2, Inc. ISC2®, ISSMP®, CISSP®, and CBK® are registered marks of ISC2, Inc. Certification names and marks are used solely to identify the certification for which these independent study materials are designed. The ISSMP exam outline and its domain structure are the property of ISC2, Inc.; candidates should download the official, current exam outline directly from isc2.org.
All course content, questions, answers, and explanations on Certifym are original content created for study purposes. They are not actual ISC2 training materials or examination questions and are not represented as such. Studying with these materials does not guarantee a passing result on any live certification exam. Exam requirements, format, domain weights, pricing, and eligibility policies are set by ISC2 and may change; always verify current details on isc2.org before scheduling your exam.
