Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISC2

Information Systems Security Management Professional

The ISSMP certification from ISC2 validates your expertise in establishing, presenting, and governing information security programs. Designed for experienced security leaders, it demonstrates deep management and leadership skills across critical functions like incident response, recovery, and risk management. Earning the ISSMP proves you can align security with organizational goals and lead with confidence.

Exam formatMultiple choice and advanced item types
Duration180 minutes
DeliveryPearson VUE
Passing score700 out of 1000
Free questions920

Content last reviewed 30 July 2026 · Up to date

The certification

What Information Systems Security Management Professional proves, and what it asks of you

What this certification covers, who it is written for, and what the exam itself looks like on the day.

6domains
30objectives
218concepts
US $199exam fee
What it is

What this certification is

What it validates, who it is written for, and the experience it assumes.

About this certification

The Information Systems Security Management Professional (ISSMP) certification is ISC2's advanced credential for security leaders who specialize in managing and governing enterprise security programs. It validates your ability to establish, present, and govern information security programs, and to demonstrate deep management and leadership skills across critical security functions such as incident response, recovery, and risk management.

ISSMP holders are recognized as experts who can align security with organizational governance, integrate security through organizational initiatives, and manage risk across the supply chain and beyond. The certification covers six domains, including leadership and organizational management, systems lifecycle management, risk management, security operations, contingency management, and law, ethics, and compliance. Earning the ISSMP distinguishes you as a leader capable of driving security strategy and resilience.

Who it’s for

The ISSMP is designed for experienced cybersecurity professionals who aspire to or currently hold senior leadership roles, such as Chief Information Security Officer, Chief Information Officer, Chief Technology Officer, or Senior Security Executive. It is ideal for those who are responsible for establishing, presenting, and governing information security programs and who want to prove their management and leadership expertise. Candidates are typically life-long learners who crave new challenges, have a competitive spirit, and want to stand out from their peers. They are looking ahead in their careers and need this certification to move into specific senior security management positions.

Recommended experience

While not mandatory, ISC2 recommends that candidates have substantial experience in information security management, including leadership roles, to successfully prepare for the ISSMP exam. Experience in establishing and governing information security programs; Leadership experience in incident response, recovery, and risk management; Familiarity with aligning security with organizational governance and initiatives; Knowledge of security operations, threat intelligence, and contingency planning

The syllabus

What you’ll learn

Every domain and objective ISC2 measures, with the weight they carry on the exam.

The official ISC2 exam outline · checked 30 July 2026 · See the source

Leadership and Organizational Management
  • 1.1 Establish security's role in organizational culture, vision, and mission
  • 1.2 Align security program with organizational governance
  • 1.3 Define and implement information security strategies
  • 1.4 Define and maintain security policy framework
  • 1.5 Manage security requirements in contracts and agreements
  • 1.6 Manage security awareness and training programs
  • 1.7 Define, measure, and report security metrics
  • 1.8 Prepare, obtain, and manage security budget
  • 1.9 Manage security programs
  • 1.10 Apply product development and project management principles
10 objectives · 306 free questions · 66 pages
Systems Lifecycle Management
  • 2.1 Manage integration of security throughout system life cycle
  • 2.2 Integrate organization initiatives and emerging technologies throughout the security architecture
  • 2.3 Define and manage comprehensive vulnerability management programs (e.g., vulnerabilities, scanning, penetration testing, threat analysis)
  • 2.4 Manage security aspects of change control
4 objectives · 115 free questions · 25 pages
Risk Management
  • 3.1 Develop and manage a risk management program
  • 3.2 Manage security risks within the supply chain (e.g., supplier, vendor, third-party risk, contracts)
  • 3.3 Conduct risk assessments
  • 3.4 Manage risk controls
4 objectives · 118 free questions · 26 pages
Security Operations
  • 4.1 Establish and maintain security operations center
  • 4.2 Establish and maintain threat intelligence program
  • 4.3 Establish and maintain incident management program
3 objectives · 110 free questions · 23 pages
Contingency Management
  • 5.1 Facilitate development of contingency plans
  • 5.2 Develop recovery strategies
  • 5.3 Maintain contingency plan, resiliency plan (e.g., Continuity of Operations Plan (COOP)), business continuity plan (BCP) and disaster recovery plan (DRP)
  • 5.4 Manage disaster response and recovery process
4 objectives · 137 free questions · 28 pages
Law, Ethics and Security Compliance Management
  • 6.1 Identify the impact of laws and regulations that relate to information security
  • 6.2 Understand, adhere to, and promote professional ethics
  • 6.3 Validate compliance in accordance with applicable laws, regulations, and industry standards
  • 6.4 Coordinate with auditors and regulators in support of internal and external audit processes
  • 6.5 Document and manage compliance exceptions
5 objectives · 134 free questions · 29 pages
On the day

The exam itself

Everything ISC2 publishes about sitting it, and nothing we inferred.

Prerequisites

Must be a CISSP in good standing (or have 7 years cumulative experience in two or more domains)

CertificationInformation Systems Security Management Professional
Exam formatMultiple choice and advanced item types
Duration180 minutes
Questions125 questions
Passing score700 out of 1000
DeliveryPearson VUE
LanguagesEnglish
PricingUS $199
Certification levelProfessional
After you pass

Where this credential goes next

The path ISC2 lays out, how the credential is kept, and where to book.

Step-by-step path to Information Systems Security Management Professional

PrerequisiteMust be a CISSP in good standing (or have 7 years cumulative experience in two or more domains)
Information Systems Security Management Professional badgeCredential earnedInformation Systems Security Management Professional Professional level certification
Renewal and maintenance

ISC2 certifications are time-limited and must be renewed on a regular three-year cycle. Certification holders maintain their credentials by earning continuing professional education (CPE) credits and complying with ISC2 policies and ethical standards. An annual maintenance fee (AMF) is also required. Stay current with the latest technologies and maintain your certification.

Learn more about renewal requirements
Lifecycle status

This certification is currently active and available. ISC2 maintains this certification to validate current skills and industry relevance.

Exam status: ActiveMaintained by ISC2

Exam registration

Register for the exam through Pearson VUE, ISC2’s authorized testing partner.

Schedule your exam

Visit the official ISC2 certification page for exam policies and requirements.

View the official page
Your coach

And when you are serious, your coach Pip takes over

Your coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.

See how the coach works
Before you book

Questions people ask

How does the ISSMP relate to the CISSP certification?

The ISSMP is a concentration certification that builds on the CISSP. Candidates must either be a CISSP in good standing with two years of experience in ISSMP domains, or have seven years of cumulative experience in two or more domains. The ISSMP focuses specifically on security management and leadership, while CISSP covers a broader range of security topics.

Is the CISSP a mandatory prerequisite for the ISSMP?

Yes, the CISSP is a mandatory prerequisite unless you have seven years of cumulative, full-time experience in two or more of the ISSMP domains. If you hold the CISSP, you need two years of experience in one or more ISSMP domains.

Can I take the ISSMP exam without holding the CISSP?

Yes, if you have a minimum of seven years of cumulative, full-time experience in two or more of the ISSMP domains. However, most candidates will hold the CISSP, which is the standard pathway.

What is the retake policy for the ISSMP exam?

ISC2's Peace of Mind Protection option includes two exam attempts with a 30-day waiting period between attempts. Standard exam purchases include one attempt, and candidates must wait 30 days before retaking the exam after a failed attempt.

Are there any hands-on or lab components in the ISSMP exam?

No, the ISSMP exam consists of multiple choice and advanced item types only. There is no hands-on or lab component.

What job roles does the ISSMP credential map to?

The ISSMP is ideal for senior security roles such as Chief Information Security Officer, Chief Information Officer, Chief Technology Officer, and Senior Security Executive.

Can I recertify the ISSMP by passing a different ISC2 exam?

No, the ISSMP must be renewed through ISC2's continuing professional education (CPE) program. Passing another exam does not automatically renew the ISSMP.

Is the ISSMP exam available in languages other than English?

Currently, the ISSMP exam is available in English only.

Information freshness · Content last reviewed on 2026-07-30 Up to date
Practice free questions 920 questions, free, no account needed.