Study Guide

ISSMP study guide: Match decisions to the right authority

Prepare for ISSMP with the six-domain map, a worked risk-authority exercise, experience routes and practical study steps.

Updated September 20266 min readStudy GuideCertBliss
Michael Parker

Michael Parker

CertBliss Editorial Team

Prepare for ISSMP by connecting security management tasks to organizational goals and decision authority. Use the six-domain map and the worked policy exercise to distinguish recommending a decision from approving it.

What the ISSMP assesses and which outline applies

The ISSMP is ISC2's credential for security leaders who establish and govern information security programs, and the current exam outline took effect on August 1, 2025.

ISC2 describes the Information Systems Security Management Professional as a security leader who specializes in establishing, presenting, and governing information security programs. The role directs how security programs align with an organization's mission, goals, and strategies so they meet financial and operational requirements while supporting the organization's desired risk position.

Use the six-domain map below to check coverage, then read the detailed objectives. The weights describe exam emphasis; combine them with your own knowledge gaps when planning study.

DomainWeight
1. Leadership and Organizational Management21%
2. Systems Lifecycle Management15%
3. Risk Management20%
4. Security Operations18%
5. Contingency Management12%
6. Law, Ethics, and Security Compliance Management14%

Verified against ISC2's official exam outline PDF and policy pages retrieved in September 2026.: ISSMP Certification Exam Outline Summary — ISC2 certification page, effective date August 1, 2025; ISSMP official English exam outline — ISC2 PDF, effective August 1, 2025

Eligibility: two experience routes

Certification has two experience routes. CISSP is required for one route, but not for both.

The first route requires an active CISSP plus two years of cumulative, full-time experience in one or more of the six domains of the current ISSMP outline. The second route requires a minimum of seven years of cumulative, full-time experience in two or more of those domains, and it does not require the CISSP.

Under the seven-year route, a qualifying degree in computer science, IT or a related field, or an approved additional credential, may satisfy one year. Only one year can be waived. Qualifying part-time work and internships may also count under ISC2’s rules.

Check your own record against these routes before booking. If you are unsure whether a role qualifies as experience in a listed domain, contact ISC2 Candidate Services rather than guessing.

Verified against ISC2's official exam outline PDF and policy pages retrieved in September 2026.: ISSMP Certification Exam Outline Summary — ISC2 certification page, effective date August 1, 2025; ISSMP official English exam outline — ISC2 PDF, effective August 1, 2025; Endorsement | Online Endorsement Application | ISC2 — ISC2 endorsement page

Exam format, scoring, and retakes

ISSMP allows three hours for 125 items in English at Pearson VUE testing centers.

The dated outline PDF lists multiple-choice questions. The current ISSMP outline webpage also lists advanced item types; check the current exam information and appointment instructions when preparing.

The passing grade is 700 out of 1000, a scaled score. It is not a raw 70% or a published number of correct answers. ISC2 does not provide numerical scores; unsuccessful candidates receive domain proficiency feedback.

An unofficial result is normally provided at checkout, followed by official notification. Results can be delayed, so avoid planning around a guaranteed turnaround.

If you need to retake, two rules apply together. After a first attempt you wait 30 test-free days; after a second attempt, 60 days; after a third and any subsequent attempt, 90 days. You may attempt the exam at most four times within any 12-month period.

Verified against ISC2's official exam outline PDF and policy pages retrieved in September 2026.: ISSMP Certification Exam Outline Summary — ISC2 certification page, effective date August 1, 2025; ISSMP official English exam outline — ISC2 PDF, effective August 1, 2025; How to Get Ready, Prepare for Your ISC2 Certification Exam — ISC2 exam preparation page; What To Do After Your ISC2 Certification Exam — ISC2 results and retake policy page

After you pass: endorsement, application, and maintenance

After passing, complete the certification application and endorsement, then meet the ongoing membership requirements.

Once your official passing email arrives, you submit a certification application that must be endorsed and digitally signed by an ISC2-certified professional in good standing who can attest to your experience. If you do not know one, ISC2 can endorse you directly, though proof of employment is required for that route. A percentage of applications is randomly audited, so keep evidence of your experience available.

The application must be completed within nine months of your exam date, and it cannot be submitted until ISC2 notifies you that you passed. Plan the endorsement around that clock, especially if you rely on a busy colleague as your endorser.

Maintenance has two parts. Certified members pay an annual maintenance fee of U.S. $135, due on the certification cycle start date and each anniversary, and earn continuing professional education (CPE) credits across a three-year cycle. One caution: the published CPE table for ISSMP and its footnote do not line up cleanly on the exact annual and three-year totals, particularly when you hold the CISSP alongside the ISSMP. Check your credential dashboard or ask ISC2 for the figure that applies to your certification combination rather than relying on a summary.

Verified against ISC2's official exam outline PDF and policy pages retrieved in September 2026.: What To Do After Your ISC2 Certification Exam — ISC2 results and retake policy page; Endorsement | Online Endorsement Application | ISC2 — ISC2 endorsement page; Member Policies — Sections 4.1-4.2, CPE and AMF requirements

The six domains as management tasks

Use these tasks to organise your review. Read the detailed objectives to identify work outside your experience.

The current ISC2 webpage also discusses AI security across the existing domains. Review that guidance alongside the dated outline; it does not create an extra weighted domain.

For practice, choose an objective and identify the decision, the responsible roles and the expected output. This is a study method, not a rule that every exam question follows one pattern.

  • Leadership and Organizational Management: review governance, security strategy, policy, contracts, awareness, metrics, budgets and project management.
  • Systems Lifecycle Management: review security across the lifecycle, configuration, emerging technologies, vulnerability management and change control.
  • Risk Management: review risk programs, risk owners, appetite and tolerance, inventories, assessments, treatment options and supply-chain risk.
  • Security Operations: review security operations centers, threat intelligence, incident management, stakeholder reporting and root-cause analysis.
  • Contingency Management: review resilience, business impact analysis, continuity, disaster recovery, crisis communications, dependencies and lessons learned.
  • Law, Ethics, and Security Compliance Management: review applicable jurisdictions, ethics, compliance frameworks, audits, exceptions and authorized risk waivers.

Verified against ISC2's official exam outline PDF and policy pages retrieved in September 2026.: ISSMP Certification Exam Outline Summary — ISC2 certification page, effective date August 1, 2025; ISSMP official English exam outline — ISC2 PDF, effective August 1, 2025

Worked exercise: who may accept the risk?

In this fictional policy, distinguish the authority to recommend risk treatment from the authority to approve it.

The outline includes risk ownership, treatment recommendations and stakeholder decisions. The exercise supplies a complete fictional assignment of authority; infer no additional power from a job title.

The worked exercise is an original fictional scenario with all premises stated.

Nortfield Logistics, a fictional company, has a written security policy that assigns four roles for its customer-portal service: risk analyst Mira assesses risks and recommends treatment; business owner Dev approves or rejects documented risk acceptance for the service; engineering lead Lin implements approved controls; and a steering group receives oversight reports. A vulnerability assessment identifies a documented risk on the portal. Mira recommends time-limited acceptance, while Lin proposes building a fix this quarter. Under this policy, who may approve acceptance of the risk, and does either Mira's recommendation role or Lin's implementation role carry approval authority? These are the complete relevant assignments; no delegation or other approval rule applies.

Try the exercise before reading the answer.

Dev, the business owner named in the policy, may approve acceptance. Neither Mira nor Lin holds approval authority: Mira's role is assessment and recommendation, and Lin's role is implementation of controls that have already been approved.

The supplied policy gives acceptance approval to Dev. Mira can recommend a treatment, Lin can implement approved controls, and the steering group receives reports. None of those other assignments grants acceptance authority. The facts do not establish whether accepting this risk is a good decision. They establish who may decide under this fictional policy; they do not create a universal rule about real business owners or job titles.

Verified against ISC2's official exam outline PDF and policy pages retrieved in September 2026.: ISSMP official English exam outline — ISC2 PDF, effective August 1, 2025

Building your preparation plan

Anchor your study to the official outline and ISC2's own self-study tools, and treat any borrowed question bank as supplementary material that needs a coverage check.

A question bank for another credential may explain overlapping concepts. Check each resource against the current ISSMP objectives rather than assuming complete coverage. Use missing objectives and weak explanations to build your gap list.

ISC2's study resources page points to credential-specific materials, including ISSMP online self-paced training, the exam outline itself, and official flash cards. The outline page also lists supplementary references for deepening specific areas. Starting from these issuer materials keeps your coverage aligned with what the exam actually tests.

One possible sequence is to read the full outline, review weaker domains, then use timed mixed practice. For each uncertain answer, explain the supplied facts and the authority or requirement involved. Adjust your plan as you find gaps.

  • Compare resources with all six domains and their detailed objectives.
  • Solve the policy exercise before revealing the answer.
  • Keep an error log by objective and revisit weak explanations.
  • Check identification, accommodations and appointment requirements before scheduling.

Verified against ISC2's official exam outline PDF and policy pages retrieved in September 2026.: ISSMP official English exam outline — ISC2 PDF, effective August 1, 2025; ISSMP Study Tools and Resources — ISC2 self-study resources page; How to Get Ready, Prepare for Your ISC2 Certification Exam — ISC2 exam preparation page

Verified against ISC2's official exam outline PDF and policy pages retrieved in September 2026.

Exam format, scoring, eligibility, retake, and maintenance facts checked against retrieved ISC2 documents.:

Next steps: confirm eligibility, download the current outline, and map your practice material to its subtasks.

FAQ

Frequently Asked Questions

Practical answers to help you apply the guidance for Information Systems Security Management Professional (ISSMP).

Keep Reading

Related Study Guides

Explore related guides and preparation topics.