CISSP-ISSEP®: Information Systems Security Engineering Professional
Your security decisions must remain consistent across the information system. Connect architecture, risks and protective measures to assess trade-offs more effectively. Strengthen your expertise to design well-founded solutions and communicate with technical teams and decision-makers alike.
- Duration
- 5 days 35 hours
- Code
- CIS03FR Code
- Certification
- CISSP® : Certified Information Systems Security Professional Certification
Accredited training for the CISSP® : Certified Information Systems Security Professional certification.
Presentation
An Information Systems Security Engineering Professional (ISSEP) is a CISSP professional specialising in the application of systems engineering principles and processes to develop secure solutions. Their role is to analyse organisational needs, define security requirements, design security architectures, develop secure models, deploy security and manage information systems security assessments in the public and private sectors.
This CISSP Concentration course explores 5 domains of the ISC2® Common Body of Knowledge (CBK®), enabling you to master the activities of security engineering. The CISSP-ISSEP training covers:
- Domain 1: systems security engineering fundamentals;
- Domain 2: risk management;
- Domain 3: security planning and design;
- Domain 4: systems implementation, verification and validation;
- Domain 5: secure operations, change management and disposal.
By the end of this 5-day course, you will also be prepared to take the (ISC)² CISSP-ISSEP examination. You can take it at our Pearson VUE centre to earn the Certified Information Systems Security Engineering Professional credential (see the Certification tab for details).

In partnership with ISC2®, Oo2 provides official, up-to-date training content. The course is delivered by an IT security expert accredited to teach CISSP-ISSEP.
Objectives
By the end of the CISSP-ISSEP course, you will be able to:
- apply systems security engineering fundamentals;
- apply standard systems security engineering processes;
- use an appropriate development methodology for each system;
- perform technical systems maintenance;
- contribute to acquisition activities;
- design Trusted Systems and Networks (TSN);
- apply security risk management principles;
- manage risks for each system;
- analyse the organisational and operational context;
- apply systems security principles;
- define system requirements;
- create reliable, effective security architectures and systems;
- implement, adapt and evolve security solutions;
- analyse and validate implemented security solutions;
- develop a secure operations strategy;
- contribute to security operations, change management and disposal processes;
- prepare effectively for the official CISSP-ISSEP examination.
Program
Domain 1: Understand information systems security engineering fundamentals
- Trustworthiness concepts and systems security engineering hierarchies.
- Relationships between systems and security engineering processes.
- Structural security design principles.
- Identify the organisational security authority.
- Elements of systems security policy.
- Design principles: open, proprietary and modular.
- Security tasks and activities.
- Verify security requirements throughout the process.
- Methods for integrating software quality assurance.
- Project planning processes.
- Project assessment and control processes.
- Decision management processes.
- Risk management processes.
- Configuration management processes.
- Information management processes.
- Implement measurement processes.
- Implement quality assurance processes.
- Identify opportunities to automate security processes.
- Prepare acquisition security requirements.
- Prepare the selection process.
- Participate in Supply Chain Risk Management.
- Develop and review contractual documentation.
- Design Trusted Systems and Networks.
Domain 2: Implement risk management
- Align security risk management with Enterprise Risk Management.
- Integrate risk management throughout the lifecycle.
- Define the risk context.
- Identify system security risks.
- Conduct risk analysis.
- Perform risk evaluation.
- Recommend risk management options.
- Provide documentation of risk findings and decisions.
- Determine stakeholder risk tolerance.
- Identify remediation requirements and other system changes.
- Determine risk treatment options.
- Assess proposed risk treatment options.
- Recommend risk treatment options.
Domain 3: Security planning and design
- Understand stakeholder needs.
- Identify relevant constraints and assumptions.
- Assess and document threats.
- Define system protection needs.
- Create security test plans (STPs).
- Resilience methods for addressing threats, including defence in depth.
- Identify fail-safe defaults.
- Reduce single points of failure (SPOFs).
- Understand least privilege.
- Understand economy of mechanism.
- Understand separation of duties (SoD).
- Develop the system security context.
- Identify system functions and the security concept of operations (CONOPS).
- Update system security requirements documentation.
- Analyse system security requirements.
- Develop functional analysis and allocation.
- Maintain traceability between the specified design and system requirements.
- Establish security system design components.
- Conduct trade-off studies.
- Assess protection effectiveness.
Domain 4: Systems implementation, verification and validation
- Implement and integrate systems security.
- Conduct systems security deployment activities.
- Verify systems security.
- Validate security to demonstrate that controls meet stakeholder security requirements.
Domain 5: Secure operations, change management and disposal
- Define requirements for operations personnel.
- Communicate continuously with stakeholders on system security issues.
- Develop continuous monitoring solutions and processes.
- Support the incident response process.
- Establish a secure maintenance strategy.
- Participate in change reviews.
- Identify change impacts.
- Verify and validate changes.
- Update risk assessment documentation.
- Identify disposal security requirements.
- Develop a secure disposal strategy.
- Develop decommissioning and disposal procedures.
- Audit the results of decommissioning and disposal.
Audience
This course is intended for:
- experienced systems engineers, information systems security managers, information security analysts and other information systems security engineering professionals.
Prerequisites
The CISSP-ISSEP course requires:
- a current CISSP credential and 2 years of cumulative professional experience in one or more of the 5 domains of the current ISSEP examination outline.
To earn CISSP certification, you can take our course:
Teaching and assessment methods
- Initial skills assessment
- Training materials provided to participants
- Continuous assessment throughout the course
- End-of-course feedback questionnaire
- Combination of theory and practical application
- Attendance records
- Post-course follow-up evaluation
- Quiz / multiple-choice questions
- Practical exercises
Course highlights
An (ISC)²-accredited trainer, official course materials, comprehensive CISSP-ISSEP certification preparation, guidance and assessment quizzes for each of the 5 domains covered.
Dates and sessions
Choose the date and delivery format that suit you.
No upcoming sessions are currently available.
Session alerts
Training content offered in partnership with (ISC)² ®
CISSP® and CISSP-ISSEP® are registered trademarks of the International Information Systems Security Certification.
fr
en