SecLeaderAcademy
← Home
ISC2 · Full exam outline
ISSEP
Information Systems Security Engineering Professional
Security engineering leadership
1
Systems Security Engineering Foundations
25%
1.1
Security engineering principles and frameworks
1.2
Stakeholder requirements and concept of operations
1.3
Systems engineering lifecycle processes
1.4
Trust and assurance concepts
2
Risk Management
14%
2.1
Risk management framework in an engineering context
2.2
Threat and vulnerability analysis
2.3
Risk treatment within the system design
3
Security Planning and Design
30%
3.1
Security requirements definition and allocation
3.2
Architecture and design decisions
3.3
Protection needs and control selection
3.4
Design trade-off analysis
4
Systems Implementation, Verification and Validation
14%
4.1
Implementation and integration of security controls
4.2
Verification and validation activities
4.3
Security assessment and test evidence
5
Secure Operations, Change Management and Disposal
17%
5.1
Secure operations and sustainment
5.2
Change and configuration management
5.3
Disposal and decommissioning
Weights are the certification body’s published values and are checked against each outline revision.