← Home
ISC2 · Full exam outline

ISSMP

Information Systems Security Management Professional

Security management / leadershipCore certification
1Leadership and Business Management22%
1.1Security governance and organizational alignment
1.2Security programme budget, metrics and reporting
1.3Roles, responsibilities and security awareness
1.4Vendor, service provider and third-party management
1.5Change and project management
2Systems Lifecycle Management19%
2.1Security in the system development lifecycle
2.2Integrate security into development and acquisition
2.3Configuration and change control
2.4System certification and accreditation
3Risk Management18%
3.1Risk management programme and methodology
3.2Risk assessment and analysis
3.3Risk treatment and reporting
3.4Continuous risk monitoring
4Threat Intelligence and Incident Management17%
4.1Threat intelligence programme
4.2Incident response plan and team readiness
4.3Incident detection, triage and response
4.4Post-incident review and forensics
5Contingency Management13%
5.1Business impact analysis
5.2Business continuity planning
5.3Disaster recovery planning
5.4Plan testing, training and maintenance
6Law, Ethics and Security Compliance Management11%
6.1Legal, regulatory and privacy requirements
6.2Compliance programme and audit management
6.3Professional ethics
6.4Security policy and standards compliance
Weights are the certification body’s published values and are checked against each outline revision.