← Home
ISC2 · Full exam outline

ISSEP

Information Systems Security Engineering Professional

Security engineering leadership
1Systems Security Engineering Foundations25%
1.1Security engineering principles and frameworks
1.2Stakeholder requirements and concept of operations
1.3Systems engineering lifecycle processes
1.4Trust and assurance concepts
2Risk Management14%
2.1Risk management framework in an engineering context
2.2Threat and vulnerability analysis
2.3Risk treatment within the system design
3Security Planning and Design30%
3.1Security requirements definition and allocation
3.2Architecture and design decisions
3.3Protection needs and control selection
3.4Design trade-off analysis
4Systems Implementation, Verification and Validation14%
4.1Implementation and integration of security controls
4.2Verification and validation activities
4.3Security assessment and test evidence
5Secure Operations, Change Management and Disposal17%
5.1Secure operations and sustainment
5.2Change and configuration management
5.3Disposal and decommissioning
Weights are the certification body’s published values and are checked against each outline revision.