ISC2 Information Systems Security Engineering Professional (ISSEP) Cert Prep by Infosec
8h 25mIntermediate2026-04-29
Authors

Infosec Institute
Course details
The Information Systems Security Engineering Professional (ISSEP) certification, a CISSP concentration, validates advanced expertise in applying systems engineering principles to design and manage secure systems throughout the System Development Life Cycle (SDLC). Certified professionals demonstrate proficiency in security architecture, risk management, and technical integration across complex environments, bridging engineering with operational and managerial processes. They are equipped to analyze trade-offs, manage risks, and implement secure designs aligned with DoD, NIST, and ISO standards.
This cert prep course covers the advanced skills and knowledge security engineers use for developing, designing, and analyzing security solutions and providing risk-based guidance. It prepares candidates for the ISSEP exam across its five domains: Systems Security Engineering Foundations, Risk Management, Security Planning and Design, Systems Implementation, Verification, and Validation, and Secure Operations, Change Management, and Disposal.
Learning objectives
Apply the information system security engineering processes as the information system security engineer on the systems engineering team.
Analyze system security risk throughout the system development life cycle within the context of system operations and organizational risk tolerance.
Analyze, design, develop, and evaluate the security design and architecture for systems using security engineering processes and principles.
Develop system solutions that employ security functions and provide adequate protection to system functions.
Choose the most effective security configurations and designs to ensure system security during operations, change management, and disposal.
This cert prep course covers the advanced skills and knowledge security engineers use for developing, designing, and analyzing security solutions and providing risk-based guidance. It prepares candidates for the ISSEP exam across its five domains: Systems Security Engineering Foundations, Risk Management, Security Planning and Design, Systems Implementation, Verification, and Validation, and Secure Operations, Change Management, and Disposal.
Learning objectives
Apply the information system security engineering processes as the information system security engineer on the systems engineering team.
Analyze system security risk throughout the system development life cycle within the context of system operations and organizational risk tolerance.
Analyze, design, develop, and evaluate the security design and architecture for systems using security engineering processes and principles.
Develop system solutions that employ security functions and provide adequate protection to system functions.
Choose the most effective security configurations and designs to ensure system security during operations, change management, and disposal.
Concepts
ISSEP Introduction
- Beginning intro to ISSEP certification
- What is an ISSEP
- Project and program management
- RMF risk management framework
- CSF cyber security framework
- Common criteria
- Core security concepts
Systems Security Engineering Foundations
- Course introduction
- Trust concepts and hierarchies
- Relationships between systems and security engineering
- Design concepts
- Organizational security authority
- System security governance and compliance
- Security tasks and activities
- Security requirements verification throughout the process
- Project management processes participation
- Configuration management processes
- Information management processes
- Measurement processes and quality assurance
- Security process automation evaluations
- Participate in technology procurement
- Resource analysis
Risk Management
- Apply security risk management principles
- Risk management integration throughout the SDLC system lifecycle
- Risk management lifecycle
- Identify system security risks using CSF
- NIST SP 800-30
- Perform risk evaluation
- Manage risk to systems
- Manage risk to operations
Security Planning and Engineering
- Analyze organizational and operational environment
- Identify roles and responsibilities
- Prepare security validation plan
- Apply system security principles
- Develop system requirements
- Identify functions within the system and security concept of operations
- Document system security baseline and requirements
- Create system security design
- Develop system security design components
Systems Security Implementation, Verification, and Validation
- Implement and integrate security solutions
- Perform security integration
- Support ongoing system security activities
- Verify successful implementation
Secure Operations, Change Management, and Disposal
- Develop secure operations plan
- Support secure operations
- Support the incident response process
- Develop secure maintenance procedures
- Participate in change management
- Assess change impact
- Perform verification and validation of changes
- Update risk assessment documentation
- Develop decommissioning disposal process
- Participate in the disposal process
- Audit results of decommissioning and disposal
- Implement data retention policies