Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2

Information Systems Security Engineering Professional

The ISSEP certification validates your ability to apply systems engineering principles and processes to develop secure systems. Developed with the U.S. National Security Agency, it proves you can incorporate security into projects, applications, business processes, and all information systems. Ideal for experienced security engineers seeking to demonstrate elite expertise and advance into specialized roles.

Exam formatMultiple choice and advanced item types
Duration180 minutes
DeliveryPearson VUE
Passing score700 out of 1000
Free questions486

Content last reviewed 30 July 2026 · Up to date

The certification

What Information Systems Security Engineering Professional proves, and what it asks of you

What this certification covers, who it is written for, and what the exam itself looks like on the day.

5domains
19objectives
115concepts
US $199exam fee
What it is

What this certification is

What it validates, who it is written for, and the experience it assumes.

About this certification

The Information Systems Security Engineering Professional (ISSEP) certification from ISC2 recognizes security leaders who specialize in the practical application of systems engineering principles to build secure systems. Developed in conjunction with the U.S. National Security Agency (NSA), the ISSEP validates your ability to analyze organizational needs, define security requirements, design security architectures, and support system security assessment and authorization for government and industry.

Earning the ISSEP demonstrates that you can execute system security engineering processes, manage technical procurement, and integrate security into every phase of the system development lifecycle. The credential covers five domains: Systems Security Engineering Foundations, Risk Management, Security Planning and Engineering, Systems Security Implementation, Verification and Validation, and Secure Operations, Change Management and Disposal. It is a mark of excellence for professionals who want to stand out as subject matter experts in security engineering.

Who it’s for

The ISSEP is designed for experienced security professionals who apply engineering principles to develop secure systems. It is ideal for those working in roles such as Senior Systems Engineer, Information Assurance Systems Engineer, Information Assurance Officer, Information Assurance Analyst, and Senior Security Analyst. You are a great fit for the ISSEP if you are a life-long learner who craves a new challenge, have a competitive spirit, want to be seen as a subject matter expert, and are looking ahead in your career. This concentration is for those who need to move into specific security engineering roles or want to achieve a higher level of success.

Recommended experience

Candidates should have a strong background in systems security engineering, with experience applying security principles across the system development lifecycle. While not mandatory, hands-on experience in security engineering roles is highly recommended. Experience in applying systems engineering processes to develop secure systems; Knowledge of security risk management, security planning, and security architecture; Familiarity with system security implementation, verification, and validation; Understanding of secure operations, change management, and disposal processes

The syllabus

What you’ll learn

Every domain and objective ISC2 measures, with the weight they carry on the exam.

The official ISC2 exam outline · checked 30 July 2026 · See the source

Systems Security Engineering Foundations
  • Apply systems security engineering fundamentals
  • Execute systems security engineering processes (e.g., hardware, software, data)
  • Integrate with system development methodology
  • Perform technical management
  • Participate in the technology procurement management
  • Resource Analysis (e.g., Cost estimation, personnel costs, probabilities and statistics (Monte Carlo))
6 objectives · 147 free questions · 31 pages
Risk Management
  • Apply security risk management principles
  • Manage risk to system
  • Manage risk to operations
3 objectives · 84 free questions · 18 pages
Security Planning and Engineering
  • Analyze organizational and operational environment
  • Apply system security principles
  • Develop system requirements
  • Create system security design
4 objectives · 104 free questions · 23 pages
Systems Security Implementation, Verification and Validation
  • Implement and integrate security solutions
  • Verify successful implementation
2 objectives · 61 free questions · 13 pages
Secure Operations, Change Management and Disposal
  • Develop secure operations plan
  • Support secure operations
  • Participate in change management
  • Participate in the disposal process
4 objectives · 90 free questions · 19 pages
On the day

The exam itself

Everything ISC2 publishes about sitting it, and nothing we inferred.

Prerequisites

Must be a CISSP in good standing

CertificationInformation Systems Security Engineering Professional
Exam formatMultiple choice and advanced item types
Duration180 minutes
Questions125 questions
Passing score700 out of 1000
DeliveryPearson VUE
LanguagesEnglish
PricingUS $199
Certification levelProfessional
After you pass

Where this credential goes next

The path ISC2 lays out, how the credential is kept, and where to book.

Step-by-step path to Information Systems Security Engineering Professional

PrerequisiteMust be a CISSP in good standing
Information Systems Security Engineering Professional badgeCredential earnedInformation Systems Security Engineering Professional Professional level certification
Renewal and maintenance

ISC2 certifications are time-limited and must be renewed on a regular three-year cycle. Certification holders maintain their credentials by earning continuing professional education (CPE) credits and complying with ISC2 policies and ethical standards. ISC2 members are also responsible for an annual maintenance fee (AMF). Stay current with the latest technologies and maintain your certification.

Learn more about renewal requirements
Lifecycle status

This certification is currently active and available. ISC2 maintains this certification to validate current skills and industry relevance.

Exam status: ActiveMaintained by ISC2

Exam registration

Register for the exam through Pearson VUE, ISC2’s authorized testing partner.

Schedule your exam

Visit the official ISC2 certification page for exam policies and requirements.

View the official page
Your coach

And when you are serious, your coach Pip takes over

Your coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.

See how the coach works
Before you book

Questions people ask

How does the ISSEP relate to the CISSP certification?

The ISSEP is a concentration certification that builds on the CISSP. Candidates must be a CISSP in good standing to earn the ISSEP, and the ISSEP demonstrates advanced expertise in security engineering.

Is the ISSEP exam available in languages other than English?

The ISSEP exam is currently available in English only.

Can I take the ISSEP exam without first earning the CISSP?

No. The ISSEP requires candidates to be a CISSP in good standing, or to have seven years of cumulative experience in two or more ISSEP domains, which is an alternative to the CISSP requirement.

What is the retake policy for the ISSEP exam?

ISC2 exam retake policies apply. Candidates who purchase the exam with Peace of Mind Protection receive two exam attempts with a 30-day waiting period between attempts. Standard retake policies are defined by ISC2 and should be reviewed on the registration page.

Are there any hands-on or lab components in the ISSEP exam?

The ISSEP exam consists of multiple choice and advanced item types. There is no hands-on lab component.

What job roles does the ISSEP certification map to?

The ISSEP is ideal for Senior Systems Engineers, Information Assurance Systems Engineers, Information Assurance Officers, Information Assurance Analysts, and Senior Security Analysts.

Can I recertify the ISSEP by passing a different ISC2 exam?

ISC2 certifications are renewed by earning CPE credits and paying the annual maintenance fee. Passing a different exam does not automatically renew the ISSEP.

Is the ISSEP exam available in all countries?

The ISSEP exam is delivered through Pearson VUE testing centers globally. Availability may vary by region; candidates should check with Pearson VUE for locations.

Information freshness · Content last reviewed on 2026-07-30 Up to date
Practice free questions 486 questions, free, no account needed.