CISSP-ISSMP®: Information Systems Security Management Professional
Cybersecurity leadership must reflect organisational risks and priorities. Structure your programme, clarify responsibilities and prepare decisions for discussion with senior leadership. Strengthen your position as a security leader beyond technical choices alone.
- Duration
- 5 days 35 hours
- Code
- CIS04FR Code
- Certification
- CISSP® : Certified Information Systems Security Professional Certification
Accredited training for the CISSP® : Certified Information Systems Security Professional certification.
Presentation
An Information Systems Security Management Professional (ISSMP) is a CISSP-certified professional who specialises in establishing, presenting and managing information security programmes. They also possess advanced governance and leadership skills. A CISSP-ISSMP aligns security programmes with an organisation's mission, objectives and strategies to meet financial and operational requirements while addressing identified risks.
This 5-day course enables you to master every aspect of information security management. It is designed for senior executives responsible for establishing, presenting and managing their security programme. It also supports professionals seeking to become Chief Technology Officers (CTOs), Chief Information Officers (CIOs) or other managers responsible for information or IT security. The CISSP-ISSMP programme covers the following 6 domains:
- leadership and business management;
- systems lifecycle management;
- risk management;
- threat intelligence and incident management;
- contingency management;
- law, ethics and security compliance management.
After this CISSP concentration course, you will be ready to take the (ISC)² CISSP-ISSMP exam to earn the Information Systems Security Management Professional credential (see the Certification tab for details).

In partnership with ISC2®, Oo2 provides official, up-to-date training content. The course is delivered by an information security expert approved to teach CISSP-ISSMP.
Objectives
By the end of CISSP-ISSMP training, you will be able to:
- understand security's importance in an organisation's culture, vision and mission;
- adapt a security plan to organisational governance;
- develop and deploy information security strategies;
- develop and maintain a security policy;
- identify applicable specific standards;
- address security requirements in contracts and agreements;
- organise security awareness training;
- design, assess and communicate security measures;
- establish, negotiate and oversee the security budget;
- manage security programmes;
- apply project management and product development principles;
- manage security implementation within the systems development lifecycle;
- incorporate new business solutions and the latest technologies into a security architecture;
- design and manage vulnerability management programmes;
- manage security issues relating to change control;
- design and manage a risk management programme;
- perform risk assessments;
- manage supply chain security risks;
- design and manage a threat intelligence programme;
- develop and manage an incident handling and investigation programme;
- promote contingency planning;
- design recovery strategies;
- maintain contingency, continuity of operations, business continuity and disaster recovery plans;
- address disaster response and recovery processes;
- identify the implications of information security laws and regulations;
- comply with the (ISC)² management Code of Ethics;
- ensure compliance with applicable regulations and industry good practice;
- coordinate auditors and regulators to facilitate internal and external audits;
- document and manage compliance exceptions;
- prepare thoroughly for the official CISSP-ISSMP exam.
Program
Domain 1: leadership and business management
- An information security programme's vision and objectives.
- Aligning security with business objectives and values.
- The relationship between security and overall business processes.
- The relationship between organisational culture and security.
- Identifying and understanding organisational governance structures.
- Validating key stakeholder roles.
- Validating sources and limits of authority.
- Advocating for and securing organisational support for security measures.
- Identifying security requirements for business projects.
- Assessing the capacity to implement security strategies.
- Implementing security strategies.
- Reviewing and sustaining security strategies.
- Recommending security concepts, architectural techniques and engineering methods.
- Identifying external standards to apply.
- Identifying data classification and protection requirements.
- Developing internal policies.
- Promoting and securing management support for policies.
- Developing procedures, standards and guidelines.
- Periodically reviewing the security policy framework.
- Assessing service management agreements
- in terms of risk and finance.
- Managing integrated services, including infrastructure and cloud services.
- Managing the effects of organisational changes: mergers, acquisitions and outsourcing.
- Ensuring compliance statements and requirements are included in contractual agreements.
- Monitoring and ensuring compliance with contractual agreements.
- Promoting security programmes to key stakeholders.
- Identifying needs and creating training programmes for target areas.
- Monitoring and reporting on the effectiveness of security awareness and training programmes.
- Identifying key performance indicators (KPIs).
- Linking KPIs to organisational risk levels.
- Using tools to manage security programme development and operations.
- Preparing and securing annual funding.
- Adjusting the budget to evolving risks and the cyberattack landscape.
- Managing and reporting on financial responsibilities.
- Defining roles and responsibilities.
- Managing team responsibilities.
- Building cross-functional relationships.
- Resolving conflicts between security and other stakeholders.
- Identifying bottlenecks and obstacles.
- Integrating security controls into HR processes.
- Integrating security into the project lifecycle.
- Identifying and implementing an appropriate project management methodology.
- Analysing the relationship between project time, scope and cost.
Domain 2: systems lifecycle management
- Integrating information security checkpoints and specifications into the lifecycle.
- Implementing security controls within the system lifecycle.
- Establishing security configuration management processes.
- Integrating security into new business initiatives and existing technology initiatives.
- The security impact of new business initiatives.
- Identifying, classifying and prioritising assets, systems and services by business criticality.
- Prioritising threats and vulnerabilities.
- Managing security testing.
- Managing risk-based vulnerability mitigation or remediation.
- Integrating security requirements into change control.
- Identifying and coordinating with stakeholders.
- Managing documentation and tracking.
- Monitoring policy implementation.
Domain 3: risk management
- Risk management programme objectives.
- Communicating and validating risk management objectives with risk owners and other stakeholders.
- The organisational scope of the risk management programme.
- Identifying organisational tolerance and capacity for security risk.
- Obtaining and verifying the organisational asset inventory.
- Performing an organisational risk analysis.
- Defining countermeasures and compensating and mitigating controls.
- Performing cost-benefit analysis and analysing risk treatment options.
- Identifying risk factors.
- Identifying supply chain security risk requirements.
- Integrating supply chain security risks into management.
- Validating the supply chain security risk control process.
- Monitoring and reviewing supply chain security risks.
Domain 4: threat intelligence and incident management
- Aggregating threat data from multiple threat intelligence sources.
- Performing baseline analysis of network traffic, data and user behaviour.
- Detecting and analysing anomalous behaviour patterns.
- Performing threat modelling.
- Identifying and classifying attack types.
- Correlating security events and threat data.
- Establishing actionable alerts for relevant resources.
- Updating programme documentation.
- Establishing an incident response case management process.
- Building an incident response team.
- Applying incident management methods.
- Creating and maintaining an incident handling process
- and an investigation process.
- Quantifying and reporting the financial and operational impact of incidents and investigations to stakeholders.
- Performing root cause analysis.
Domain 5: security incident management
- Identifying and analysing continuity of operations and business continuity plan elements.
- Identifying and analysing disaster recovery plan elements.
- Coordinating crisis management plans with key stakeholders.
- Creating internal and external crisis communication plans.
- Defining and communicating emergency roles and responsibilities.
- Identifying and analysing the impact of emergency measures on business processes and priorities.
- Managing third-party dependencies during emergencies.
- Preparing a security management succession plan.
- Identifying and analysing alternatives.
- Recommending and managing recovery strategies.
- Assigning recovery roles and responsibilities.
- Planning tests, assessments and changes.
- Defining resistance and resilience options.
- Managing the plan update process.
- Declaring an incident.
- Implementing the plan.
- Resuming normal operations.
- Updating the plan based on lessons learned.
Domain 6: law, ethics and security compliance management
- Identifying applicable privacy regulations, including the GDPR.
- Identifying the jurisdictions governing organisations and users in their operations.
- Identifying export laws.
- Identifying intellectual property laws.
- Identifying applicable industry standards.
- Identifying and advising on non-compliance risks.
- Adhering to the (ISC)² management Code of Ethics.
- Communicating required measures to organisational leadership.
- Assessing and selecting compliance frameworks.
- Implementing compliance frameworks.
- Creating and monitoring compliance measures.
- Planning an audit.
- Coordinating audit activities.
- Assessing and validating audit findings.
- Formulating responses.
- Validating mitigation and remediation measures.
- Identifying and documenting compensating controls and workarounds.
- Reporting and validating risk waivers.
Audience
This course is intended for:
- Chief Information Officers (CIOs), IT directors, information security managers, Chief Technology Officers (CTOs) and other senior information systems security leaders.
Prerequisites
The following prerequisites apply to CISSP-ISSMP training:
- an active CISSP credential and 2 years of cumulative professional experience in one or more of the 6 (ISC)² CBK domains.
To earn CISSP certification, you can take our course:
Teaching and assessment methods
- Initial skills assessment
- Training materials provided to participants
- Continuous assessment throughout the course
- End-of-course feedback questionnaire
- Combination of theory and practical application
- Attendance records
- Post-course follow-up evaluation
- Quiz / multiple-choice questions
- Practical exercises
Course highlights
An (ISC)²-approved trainer, official course materials, comprehensive CISSP-ISSMP certification preparation, advice and assessment quizzes for each of the 6 domains.
Dates and sessions
Choose the date and delivery format that suit you.
No upcoming sessions are currently available.
Session alerts
Training content offered in partnership with (ISC)²®
CISSP® and CISSP-ISSMP® are registered trademarks of International Information Systems Security Certification.
fr
en