ISC2 Information Systems Security Engineering Professional (ISSEP) focuses on the engineering processes used to build security into complex systems throughout their lifecycle. It is intended for experienced professionals who translate security requirements into technical designs, integrate controls across system components, and verify that security objectives are met from initial planning through operations and disposal.
The curriculum addresses systems security engineering foundations, risk management, security planning and engineering, implementation, verification and validation, and secure operations and change management. Participants examine how security requirements are derived, documented, and incorporated into hardware, software, data, and infrastructure. The training also covers architecture and design decisions, technical risk analysis, system integration, testing, assurance, configuration control, sustainment, and the secure retirement of systems.
Security engineers, systems engineers, security architects, technical consultants, and other professionals responsible for engineering secure systems are the primary audience. Candidates may qualify with an active CISSP and two years of relevant experience or with seven years of cumulative experience across the ISSEP domains. Organizations can use ISSEP training to strengthen security engineering practices, improve coordination between engineering and cybersecurity teams, and develop staff capable of integrating security into complex systems from concept through end of life.