Skip to content

Information Systems Security Management Professional (ISSMP)

Professional training. Expert instructors. Better value. No compromises.

CY-012 Live Instructor-Led Training
ISC2 4 Days 32 Hours
$1,799

Expert Training. Better Value.

Why pay $4,295 elsewhere?

Pricing shown is for individual enrollment.

Training a Team?

Ask us about group pricing, custom scheduling, and focused delivery.

Contact Us

ISC2 Information Systems Security Management Professional (ISSMP) addresses the leadership and management responsibilities involved in building, governing, and sustaining an enterprise cybersecurity program. It is intended for experienced professionals who oversee security strategy, policy, risk, operations, and organizational resilience, along with organizations developing senior security leaders.

The curriculum covers leadership and business management, systems lifecycle management, risk management, threat intelligence and incident management, contingency management, and legal, regulatory, and ethical requirements. Participants examine how security programs are aligned with organizational objectives, how policies and governance structures are established, and how risk is managed across technology, personnel, suppliers, and business operations. The training also addresses incident leadership, continuity planning, recovery, security metrics, budgeting, and communication with executives and other stakeholders.

Security managers, directors, program leaders, consultants, and other professionals responsible for enterprise security management are the primary audience. Candidates may qualify through an active CISSP and two years of relevant experience or through seven years of experience across the ISSMP domains. For organizations, ISSMP training helps develop leaders who can connect cybersecurity priorities with business strategy, manage complex security programs, and guide teams through operational, regulatory, and organizational change.

Course Objectives

What you will learn

Domain 1: Leadership and Operational Management

  • Establish security's role in organizational culture, vision, and mission.
  • Align security program with organizational governance.
  • Define and implement information security strategies.
  • Define and maintain security policy framework.
  • Manage security requirements in contracts and agreements.
  • Manage security awareness and training programs.
  • Define, measure and report security metrics.
  • Prepare, obtain, and manage security budget.
  • Manage security programs.
  • Apply product development and project management principles.

Domain 2: Systems Lifecycle Management

  • Manage integration of security throughout system life cycle.
  • Integrate organization initiatives and emerging technologies throughout the security architecture.
  • Define and manage comprehensive vulnerability management programs.
  • Manage security aspects of change control.

Domain 3: Risk Management

  • Develop and manage a risk management program.
  • Manage security risks within the supply chain.
  • Conduct risk assessments.
  • Manage risk controls.

Domain 4: Security Operations

  • Establish and maintain security operations center.
  • Establish and maintain threat intelligence program.
  • Establish and maintain incident management program.

Domain 5: Contingency Management

  • Facilitate development of contingency plans.
  • Develop recovery strategies.
  • Maintain contingency plan, resiliency plan, business continuity plan (BCP) and disaster recovery plan (DRP).
  • Manage disaster response and recovery process.

Domain 6: Law, Ethics and Security Compliance Management

  • Identify the impact of laws and regulations that relate to information security.
  • Understand, adhere to, and promote professional ethics.
  • Validate compliance in accordance with applicable laws, regulations, and industry standards.
  • Coordinate with auditors and regulators in support of internal and external audit processes.
  • Document and manage compliance exceptions.