CISSP-ISSMP

CISSP-ISSMP

The Information Systems Security Management Professional concentration targets security leaders who manage programs rather than implement technical controls. Before pursuing ISSMP, you should understand what it provides and whether the investment makes sense for your situation. The certification has a specific niche, and for many security professionals, other credentials may serve their career goals more effectively.

I will describe ISSMP accurately so you can make an informed decision. It is not a universally valuable credential. Whether it benefits you depends entirely on your career context and goals.

What Is CISSP-ISSMP?

The ISSMP is one of three CISSP concentrations offered by ISC2. It focuses on establishing, presenting, and governing security programs at the organizational level. The target audience is security managers, directors, and those responsible for security program oversight rather than technical implementation.

ISSMP requires an active CISSP certification. This prerequisite means you have already demonstrated broad security knowledge. ISSMP adds a management specialization on top of that foundation.

The certification is recognized under DoD 8570/8140 for certain management positions. However, its recognition is narrower than CISSP itself or other management certifications like CISM.

The Value Proposition: An Honest Assessment

ISSMP occupies an unusual position in the certification landscape. Here are the factors to consider.

CISSP already covers management concepts. The Security and Risk Management domain of CISSP addresses governance, compliance, and security program management. ISSMP goes deeper on these topics, but for many positions, CISSP alone demonstrates sufficient management capability.

CISM from ISACA competes directly with ISSMP and has broader industry recognition. If you are pursuing a management-focused credential to complement CISSP, CISM is more widely recognized and requested in job postings. Many hiring managers know CISM; fewer specifically seek ISSMP.

The DoD recognition for ISSMP is limited. While it satisfies certain 8570/8140 requirements, CISSP alone meets most management-level requirements. Adding ISSMP does not dramatically expand your compliance coverage.

Study resources for ISSMP are limited compared to CISSP or CISM. Fewer books, courses, and practice exams exist. Preparation can be more difficult simply due to resource scarcity.

ISSMP may provide value if you specifically need it for a contract requirement, want to demonstrate management specialization within the ISC2 ecosystem, or are collecting concentrations for professional distinction. For most security managers, the effort may be better directed toward CISM or other credentials.

What Does the Exam Cover?

The ISSMP exam covers six domains focused on security program management:

Leadership and Business Management (22%) – Aligning security with business objectives, security governance, strategic planning, and organizational dynamics. Managing security as a business function.

Systems Lifecycle Management (19%) – Integrating security into system development, acquisition, and maintenance processes from a management perspective.

Risk Management (18%) – Enterprise risk assessment, risk treatment, and communicating risk to stakeholders. Managing risk at the organizational level rather than technical assessment.

Threat Intelligence and Incident Management (17%) – Building threat intelligence programs, managing incident response capabilities, and crisis management.

Contingency Management (10%) – Business continuity, disaster recovery, and organizational resilience from a management perspective.

Law, Ethics, and Security Compliance Management (14%) – Legal considerations, regulatory compliance, and ethical management of security programs.

Certification Diagram

Who Should Get ISSMP?

ISSMP makes sense in limited circumstances. If a specific contract or position requires ISSMP, pursue it. If you hold CISSP and ISSEP and want to complete the concentration set, ISSMP adds consistency. If your organization values ISC2 credentials and you want to demonstrate management specialization within that framework, ISSMP serves that purpose.

For most security managers and directors, CISM provides broader recognition with a similar focus. If you do not have CISSP yet, pursue CISSP first. If you have CISSP and want a management credential, evaluate whether CISM better serves your goals before committing to ISSMP.

Security professionals early in their careers should not pursue ISSMP. Build experience, earn CISSP, and then evaluate whether management concentrations align with your career direction.

Exam Details

  • Exam Code: CISSP-ISSMP
  • Number of Questions: 125
  • Question Types: Multiple choice
  • Time Limit: 3 hours
  • Passing Score: 700 out of 1000
  • Cost: $599 USD
  • Prerequisite: Active CISSP certification

The exam format mirrors other CISSP concentrations. Questions focus on management decision-making rather than technical implementation.

Preparation Approach

If you decide ISSMP aligns with your goals, approach preparation systematically despite limited resources.

The ISC2 Official ISSMP Study Guide is the primary resource. It covers all domains but may require supplementation for certain topics.

Review NIST SP 800-100 (Information Security Handbook: A Guide for Managers). It addresses security management from a federal perspective and provides context for exam topics.

Business continuity and disaster recovery publications from NIST and other sources supplement the contingency management domain. Understanding these topics at a management level rather than technical implementation is key.

Your CISSP study materials remain relevant. ISSMP builds on CISSP knowledge, so review Security and Risk Management concepts before diving into ISSMP-specific material.

Practice exams are scarce. Focus on understanding concepts thoroughly so you can reason through unfamiliar questions. The management perspective means applying judgment, not memorizing procedures.

Test Day Execution

ISSMP tests management thinking. Questions present organizational scenarios requiring leadership decisions. Think about business alignment, stakeholder communication, and programmatic responses rather than technical fixes.

When multiple answers seem correct, choose the response that addresses the issue at the organizational level rather than the technical level. ISSMP wants to see that you think like a security program leader.

Time management matters. Three hours for 125 questions requires steady progress without rushing.

What Comes After ISSMP?

ISSMP positions you for security director, CISO, and security program manager roles where demonstrated management capability matters. For positions that specifically require ISSMP, it satisfies that requirement.

Consider whether additional certifications add value. If you have CISSP and ISSMP, CISM may be redundant. If you want to demonstrate technical depth alongside management capability, ISSEP provides that balance.

Career advancement beyond ISSMP depends on demonstrated performance in management roles. The certification validates knowledge; your track record demonstrates results. Focus on delivering security program outcomes while using certifications to establish baseline credibility.

ISSMP is a tool for specific purposes. Use it if those purposes align with your situation. If they do not, direct your effort toward credentials that provide greater return on investment.

Daniel Griggs

Retired Army Chief Warrant Officer. Twenty years in cyber ops. Now in government consulting.

Leave a Reply

Your email address will not be published. Required fields are marked *