ISC2 Information Systems Security Management Professional (ISSMP) addresses the leadership and management responsibilities involved in building, governing, and sustaining an enterprise cybersecurity program. It is intended for experienced professionals who oversee security strategy, policy, risk, operations, and organizational resilience, along with organizations developing senior security leaders.
The curriculum covers leadership and business management, systems lifecycle management, risk management, threat intelligence and incident management, contingency management, and legal, regulatory, and ethical requirements. Participants examine how security programs are aligned with organizational objectives, how policies and governance structures are established, and how risk is managed across technology, personnel, suppliers, and business operations. The training also addresses incident leadership, continuity planning, recovery, security metrics, budgeting, and communication with executives and other stakeholders.
Security managers, directors, program leaders, consultants, and other professionals responsible for enterprise security management are the primary audience. Candidates may qualify through an active CISSP and two years of relevant experience or through seven years of experience across the ISSMP domains. For organizations, ISSMP training helps develop leaders who can connect cybersecurity priorities with business strategy, manage complex security programs, and guide teams through operational, regulatory, and organizational change.