ZETLAN TECHNOLOGIES
Course Categories 172+
Cloud & Infrastructure 7
Networking 8
Virtualisation 5
IT Security 10
CyberSecurity & Mgmt 14
Software Development 16
Web Dev & Database 27
Data Science & AI 14
Mobile, Testing & Games 22
Design & Creative 49
Navigation
Home Business About Us Contact Us All Courses FAQ & Help
Contact Us
+91 8680961847 +91 8680961847 (WhatsApp) info@zetlantechnologies.com
Browse by Domain
Cloud & Infrastructure 7
Networking 8
Virtualisation 5
IT Security 10
CyberSecurity & Mgmt 14
Software Development 16
Web Dev & Database 27
Data Science & AI 14
Mobile, Testing & Games 22
Design & Creative 49
2000+ Courses · 15+ Technology Domains
Microsoft Cisco AWS EC-Council View All Courses
Home  /  ISC2 Certifications  /  ISSMP
👔 CISSP Concentration · Executive Level

ISC2 Information Systems Security
Management Professional (ISSMP)

Prove your knowledge and leadership skills across critical security management functions. The ISSMP is the ISC2 concentration for CISSP holders who establish, present and govern information security programmes at the executive level.

Security Management CISSP Concentration Executive Leadership Risk Management Incident Management CISO Level
Enroll Now
Security LeadershipStrategy, governance & programme management
Risk ManagementOrganisational risk & supply chain risk
Incident ManagementThreat intelligence & IR programme
Contingency ManagementBC/DR planning & recovery strategies
125
Exam Questions
3 Hrs
Duration
Active CISSP
Prerequisite
6
Domains
Why It's Valuable

The Executive Security Management Credential

ISSMP validates the leadership and management skills that security executives need to govern enterprise-wide security programmes and lead organisations through critical security decisions.

C-Suite
Executive Pathway
ISSMP is the recognised credential for CISOs, CIOs and senior security executives leading enterprise security programmes.
Trending
Strategic
Programme Governance
Demonstrates your ability to establish, present and govern organisation-wide information security programmes.
6
Management Domains
Covers leadership, systems lifecycle, risk, threat intelligence, contingency management and legal compliance.
Trending
CISSP
Concentration
Requires an active CISSP, positioning ISSMP as a mark of elite management expertise for seasoned professionals.
Certification

ISC2 Information Systems Security Management Professional (ISSMP)

ISSMP — Information Systems Security Management Professional

The ISSMP is a CISSP concentration that demonstrates deep management and leadership skills across critical security functions including incident response, recovery and programme governance. It shows that you excel at establishing, presenting and governing information security programmes at the most senior levels.

Prerequisite: Active CISSP certification in good standing. Experience: Two years of cumulative paid work experience in one or more of the six ISSMP domains. Ideal for: Chief Information Officer, Chief Information Security Officer, Chief Technology Officer, Senior Security Executive.

Exam Overview

ISSMP — Security Management Professional Exam Details

Language
English
Duration
180 Minutes
Total Questions
125
Passing Score
700 out of 1000
Format
Multiple Choice
Prerequisite
Active CISSP Certification

Exam details may change. Refer to the official ISC2 website for the latest information on pricing and policies.

Course Content

Complete ISSMP Curriculum

Click any domain to expand and explore the topics covered in detail.

01
Leadership and Business Management
7 Topics
Establish security's role in organisational culture, vision and mission
Align security programme with organisational governance and stakeholder roles
Define and implement information security strategies aligned to business initiatives
Define and maintain security policy framework: standards, guidelines and baselines
Manage security requirements in contracts, SLAs and outsourcing agreements
Manage security awareness and training programmes and report effectiveness metrics
Prepare, obtain and administer security budget aligned to evolving risk landscape
02
Systems Lifecycle Management
5 Topics
Manage integration of security into Systems Development Life Cycle (SDLC)
Integrate new business initiatives and emerging technologies into security architecture
Define and oversee comprehensive vulnerability management programmes
Prioritise threats, vulnerabilities and manage security testing activities
Manage security aspects of change control and ensure continuous policy compliance
03
Risk Management
5 Topics
Develop and manage a risk management programme with defined objectives and scope
Identify organisational risk tolerance, appetite and asset inventory
Analyse organisational risks and determine countermeasures and compensating controls
Perform cost-benefit analysis (CBA) of risk treatment options
Manage security risks within the supply chain: vendor, supplier and third-party risk
04
Threat Intelligence and Incident Management
6 Topics
Establish and maintain a threat intelligence programme: data aggregation and analysis
Conduct baseline analysis of network traffic, data and user behaviour
Detect and correlate anomalous behaviour patterns and create actionable alerting
Establish and maintain incident response case management and IR team
Quantify and report financial and operational impact of incidents to stakeholders
Conduct root cause analysis (RCA) and incorporate lessons learned
05
Contingency Management
6 Topics
Facilitate development of Continuity of Operations Plan (COOP) and Business Continuity Plan
Facilitate Disaster Recovery Plan (DRP) development and coordinate with stakeholders
Define internal and external crisis communications plans and succession planning
Develop recovery strategies and assign recovery roles and responsibilities
Maintain and test contingency plans including survivability and resiliency assessment
Manage disaster response, implementation, restoration and lessons learned process
06
Law, Ethics and Security Compliance Management
6 Topics
Identify impact of privacy laws, export laws, intellectual property and industry regulations
Adhere to the ISC2 Code of Ethics as related to management issues
Validate compliance with applicable laws, regulations and industry best practices
Evaluate and select compliance frameworks and define compliance metrics
Coordinate with auditors and regulators for internal and external audit processes
Document and manage compliance exceptions with authorised risk waiver approval
FAQs

Frequently Asked Questions

What is the ISSMP certification?
The ISSMP (Information Systems Security Management Professional) is an ISC2 CISSP concentration for senior security executives and managers. It validates deep leadership and management skills across critical security functions including incident response, business continuity and programme governance.
Who is eligible for the ISSMP?
Candidates must hold an active CISSP certification in good standing and have two years of cumulative paid work experience in one or more of the six ISSMP domains. The ISSMP is ideal for CISOs, CIOs, CTOs and Senior Security Executives.
What is the ISSMP exam format?
The ISSMP exam consists of 125 multiple choice questions to be completed within 180 minutes. A score of 700 out of 1000 is required to pass. The exam is administered through Pearson VUE.
How does ISSMP differ from ISSAP and ISSEP?
All three are CISSP concentrations, but they focus on different disciplines. ISSAP focuses on architecture, ISSEP on engineering, and ISSMP on management and leadership. ISSMP is the most appropriate for executives and programme managers at the C-suite level.
What executive roles does ISSMP support?
ISSMP is designed for senior roles including Chief Information Officer (CIO), Chief Information Security Officer (CISO), Chief Technology Officer (CTO), Senior Security Executive and Security Programme Manager.
Does ISSMP need to be renewed?
Yes — the ISSMP is renewed alongside your CISSP every three years. You must earn Continuing Professional Education (CPE) credits and pay the Annual Maintenance Fee (AMF) to maintain both credentials in good standing.
Get Started

Lead Enterprise Security at the Executive Level with ISSMP

Join Zetlan Technologies' ISSMP programme and develop the management and leadership skills that organisations need from their senior security executives and programme leaders.

Zetlan Technologies
Online — Replies in minutes
👋 Hi! Welcome to Zetlan Technologies.

Interested in ISSMP — ISC2 Information Systems Security Management Professional? Ask us anything!
Just now
Course Details? Batch Timings? Exam Details
Open WhatsApp Chat
Your info is safe with us
💬 Chat with us!