The Information Systems Security Engineering Professional concentration exists for one reason: to validate that you can engineer security into systems from the ground up. This is not about managing security programs or responding to incidents. ISSEP is about building systems that are secure by design, following rigorous engineering processes that the federal government requires for its most sensitive programs.
I pursued ISSEP because my work on defense programs demanded it. When you are engineering systems that protect national security, you cannot retrofit security after the fact. ISSEP teaches and validates the discipline required to integrate security throughout the system development lifecycle. The National Security Agency developed this concentration specifically for systems security engineers working on classified programs.
What Is CISSP-ISSEP?
The ISSEP is one of three CISSP concentrations offered by ISC2. It focuses on the practical application of systems engineering principles to build secure information systems. The concentration was developed in partnership with the NSA and reflects the security engineering requirements for government systems.
ISSEP requires an active CISSP certification. You cannot pursue ISSEP without first earning CISSP and maintaining it in good standing. This prerequisite ensures that ISSEP holders have demonstrated broad security knowledge before specializing in engineering.
The certification is specifically recognized under DoD 8570/8140 for IASAE Level II positions. For contractors and government civilians working on system engineering for defense and intelligence programs, ISSEP often appears as a contract requirement.
What Does the Exam Cover?
The ISSEP exam covers five domains focused on security engineering throughout the system lifecycle:
Systems Security Engineering Foundations (25%) – Security engineering principles, system lifecycle processes, and the integration of security into engineering methodologies. Understanding NIST SP 800-160 and similar frameworks.
Risk Management (14%) – Risk assessment methodologies, threat modeling, and risk treatment strategies specific to system engineering. Making engineering decisions based on risk analysis.
Security Planning and Design (30%) – The largest domain. Security requirements development, security architecture, and design principles. Translating security requirements into system specifications.
Systems Implementation, Verification, and Validation (14%) – Security testing, verification of security controls, and validation that systems meet security requirements.
Secure Operations, Change, and Disposal (17%) – Maintaining security through operations, managing change securely, and secure system disposal at end of life.
Who Should Get ISSEP?
ISSEP is for systems security engineers, security architects, and technical leads who design and engineer secure systems. If your work involves developing security requirements, designing security architectures, or ensuring systems meet security standards throughout development, ISSEP validates that expertise.
The certification is particularly valuable for professionals working on government and defense programs. Contracts for the Department of Defense, intelligence community, and other federal agencies frequently require ISSEP for security engineering positions.
If you are a CISSP holder working in system development rather than operations or management, ISSEP demonstrates your specialized engineering focus. It distinguishes you from general security professionals who may understand security concepts but lack engineering discipline.
ISSEP is not appropriate for security administrators, SOC analysts, or IT generalists. It targets a specific audience: engineers who build systems with security integrated from conception through disposal.
Exam Details
- Exam Code: CISSP-ISSEP
- Number of Questions: 125
- Question Types: Multiple choice
- Time Limit: 3 hours
- Passing Score: 700 out of 1000
- Cost: $599 USD
- Prerequisite: Active CISSP certification
The exam is shorter than the CISSP but covers material at greater depth within the engineering domain. Candidates with strong engineering backgrounds will find the content familiar; those coming from operations or management tracks will need significant study.
Preparation Approach
ISSEP preparation should build on your existing CISSP knowledge while deepening understanding of systems engineering processes.
The NIST SP 800-160 (Systems Security Engineering) is essential reading. This publication defines the processes and practices that ISSEP tests. Read it thoroughly and understand how security engineering integrates with general systems engineering.
Review the Risk Management Framework documentation, particularly NIST SP 800-37. Understanding how RMF applies to system development provides context for many exam questions.
The ISC2 Official ISSEP Study Guide covers all domains. Use it as your primary study resource, supplementing with NIST publications and engineering standards where the guide references them.
If you have not worked extensively with formal system development processes, study the general systems engineering lifecycle. Understanding V-model, spiral development, and agile approaches—and how security integrates with each—prepares you for exam scenarios.
Practice questions for ISSEP are less abundant than for CISSP. Focus on understanding concepts rather than memorizing question banks. If you understand how to apply security engineering principles, you can reason through questions you have not seen before.
Test Day Execution
ISSEP questions test your ability to apply engineering principles to security problems. Expect scenario-based questions that describe a system development situation and ask for the appropriate security engineering response.
Think like an engineer, not an operator. Questions ask what you should build into a system, not how to respond after deployment. The correct answer involves systematic analysis and design, not reactive measures.
Pay attention to lifecycle phase. The correct answer for a system in requirements definition differs from the correct answer for a system in operations. Context determines the appropriate action.
Three hours for 125 questions requires steady progress. Do not spend excessive time on any single question. Make your best determination and continue.
What Comes After ISSEP?
ISSEP positions you for senior security engineering roles in government and defense programs. Systems security engineer, security architect, and technical lead positions often require or prefer ISSEP.
Within the CISSP concentration family, ISSAP focuses on architecture at a broader level than engineering. Some professionals hold both to demonstrate capabilities across architecture and implementation.
For government careers, ISSEP satisfies 8570/8140 requirements at senior technical levels. Combined with CISSP, it covers most certification requirements for security engineering positions.
Professional growth beyond ISSEP involves expanding your engineering expertise into specific domains—cloud architecture, zero trust implementation, or emerging technology areas. The certification demonstrates foundational capability; continued learning keeps skills current.
ISSEP holders often advance to chief engineer, principal security architect, or senior technical advisor positions. The certification validates that you can lead the engineering effort to build secure systems, which is exactly what programs handling sensitive information require.
Retired Army Chief Warrant Officer. Twenty years in cyber ops. Now in government consulting.
Leave a Reply