Skip to content

Systems Security Certified Practitioner (SSCP)

Professional training. Expert instructors. Better value. No compromises.

CY-007 Live Instructor-Led Training
ISC2 5 Days 40 Hours
$2,199

Expert Training. Better Value.

Why pay $3,875 elsewhere?

Pricing shown is for individual enrollment.

Training a Team?

Ask us about group pricing, custom scheduling, and focused delivery.

Contact Us

ISC2 Systems Security Certified Practitioner (SSCP) develops the technical knowledge and operational skills required to implement, monitor, and maintain cybersecurity controls across enterprise systems. It is intended for professionals working directly with security technologies and processes, as well as organizations developing administrators, analysts, and other practitioners responsible for protecting information systems.

The curriculum spans security concepts and practices, access controls, risk identification and monitoring, incident response and recovery, cryptography, network and communications security, and systems and application security. Participants examine how security controls are selected and applied, how access is managed, how threats and vulnerabilities are identified, and how incidents are investigated and contained. The training also addresses secure system administration, network protection, encryption, monitoring, recovery planning, and the day-to-day practices that support an effective security program.

SSCP is designed for systems administrators, security analysts, network and systems analysts, database administrators, and other IT professionals with hands-on security responsibilities. ISC2 requires one year of relevant work experience for certification, although qualifying education may satisfy that requirement. Organizations can use SSCP training to strengthen frontline security capabilities, establish consistent operational practices, and prepare technical staff to take on broader responsibilities in security administration, monitoring, incident response, and risk management.

Course Objectives

What you will learn

Domain 1: Security Concepts and Practices

  • Comply with codes of ethics.
  • Understand security concepts.
  • Identify and implement security controls.
  • Document and maintain functional security controls.
  • Support and implement asset management lifecycle (i.e., hardware, software, and data).
  • Support and/or implement change management lifecycle.
  • Support and/or implement security awareness and training.
  • Collaborate with physical security operations.

Domain 2: Access Controls

  • Implement and maintain authentication methods.
  • Understand and support internetwork trust architectures.
  • Support and/or implement the identity management lifecycle.
  • Understand and administer access controls.

Domain 3: Risk Identification, Monitoring and Analysis

  • Understand risk management.
  • Understand legal and regulatory concerns.
  • Perform security assessments and vulnerability management activities.
  • Operate and monitor security platforms.
  • Analyze monitoring results.

Domain 4: Incident Response and Recovery

  • Understand and support incident response lifecycle.
  • Understand and support forensic investigations.
  • Understand and support business continuity plan (BCP) and disaster recovery plan (DRP) activities.

Domain 5: Cryptography

  • Understand reasons and requirements for cryptography.
  • Apply cryptography concepts.
  • Understand and implement secure protocols.
  • Understand and support public key infrastructure (PKI) systems.

Domain 6: Network and Communications Security

  • Understand and apply fundamental concepts of networking.
  • Understand network attacks.
  • Manage network access controls.
  • Manage network security.
  • Operate and configure network-based security appliances and services.
  • Secure wireless communications.
  • Secure and monitor Internet of Things (IoT).

Domain 7: Systems and Application Security

  • Identify and analyze malicious code and activity.
  • Implement and operate endpoint device security.
  • Endpoint detection and response (EDR).
  • Understand and configure cloud security.
  • Operate and maintain secure virtual environments.