ISSMP is ISC2’s advanced credential for professionals who manage enterprise security programs, rather than just securing individual systems. kodestree’s ISSMP certification training takes you through all six domains of the current exam outline, leadership, systems lifecycle, risk, threat intelligence, contingency planning, and compliance, using real management scenarios, so you walk into the exam having practiced the judgment calls it actually tests, not just memorized definitions.
Prerequisites
There’s no fixed academic prerequisite to join the training itself, but ISC2 does set experience requirements to sit for the actual certification exam. As of the 2023 policy change, candidates can qualify through either path:
- Path 1: Hold an active CISSP and have at least 2 years of cumulative, full-time paid experience in one or more of the ISSMP domains.
- Path 2: No CISSP required- have at least 7 years of cumulative, full-time paid experience across two or more of the ISSMP domains.
- A working understanding of security fundamentals (gained through roles in security management, IT governance, risk, or compliance) makes the training easier to apply, even though it isn’t a strict enrolment requirement.
Why Learn ISSMP
A few reasons this concentration is worth the effort right now:
- Boards and regulators increasingly hold named individuals accountable for cyber risk, and ISSMP is built specifically around that leadership and governance layer.
- ISC2 refreshed the ISSMP exam outline in August 2025 to align with how security programs are actually implemented today, ensuring the certification reflects current practice rather than outdated theory.
- It’s one of the few credentials that tests business alignment, budgeting, and stakeholder management alongside security – skills CISSP alone doesn’t dig into.
- Opening the path to non-CISSP holders (7-year track) has widened who can realistically pursue it, without lowering what it validates.
- GRC, security program management, and CISO-track roles continue to be among the more resilient hiring categories in Cyber Security, and ISSMP is a recognized signal for those tracks.
Course Objectives
By the end of this training, you’ll be able to:
- Explain and apply all six ISSMP domains in real organizational contexts
- Align a security program’s goals, budget, and reporting with business strategy
- Build and evaluate risk treatment, vulnerability management, and supply-chain risk approaches
- Plan for incident response, threat intelligence integration, and crisis communication
- Design contingency, business continuity, and disaster recovery strategies
- Walk into the ISC2 ISSMP exam with practiced, scenario-tested judgment
What You Will Learn
The course is organized around ISC2’s six ISSMP domains:
- Leadership and Business Management – governance, strategy alignment, security culture, and budgeting
- Systems Lifecycle Management – embedding security into SDLC, change control, and vendor/procurement decisions
- Risk Management – risk assessment methods, treatment plans, and third-party/supply-chain risk
- Threat Intelligence and Incident Management – building threat intel programs and leading incident response
- Contingency Management – business continuity, disaster recovery, and continuity-of-operations planning
- Law, Ethics, and Security Compliance Management – regulatory obligations, investigations, and the ISC2 Code of Ethics
Who Is this Course For?
This training is built for people already operating at, or moving into, a security leadership seat:
- CISSP holders looking to add a management-focused concentration
- Security managers, directors, and heads of security
- GRC leads, risk managers, and compliance officers
- Aspiring CISOs, deputy CISOs, and IT security directors
- Incident response and business continuity leads moving into broader program ownership
Tools & Frameworks You Will Work With
- NIST Cybersecurity Framework (CSF) and related risk guidance
- ISO/IEC 27001 and related information security management standards
- COBIT for IT governance alignment
- GRC platforms such as RSA Archer and ServiceNow GRC (concepts and use cases)
- Business continuity/DR planning templates and tabletop exercise formats
- Incident response and threat intelligence workflow models
Skills You Will Gain
Beyond exam readiness, you’ll walk away with practical skills such as:
- Translating security risk into business language for executives and boards
- Structuring and running enterprise-wide security programs
- Leading incident response and post-incident reviews
- Building and testing business continuity and disaster recovery plans
- Managing vendor, supply-chain, and third-party security risk
- Applying legal, regulatory, and ethical judgment to security decisions
Career Outcomes
An ISSMP concentration is generally used to move into, or get recognized for, roles such as:
- Information Security Manager / Director
- Security Program Manager
- GRC Manager or Risk Manager
- CISO or Deputy CISO
- IT Security Compliance Manager
- Business Continuity / Disaster Recovery Manager
Why Choose kodestree for This Training?
A few reasons professionals train with kodestree for certifications like this:
- Live, instructor-led sessions with trainers who’ve worked in GRC and security leadership roles, not just taught theory
- Case studies and scenarios drawn from real security programs, matched to how the ISSMP exam is actually structured
- Flexible batch timings for working professionals, with recordings for revision
- Post-training support while you prepare for and schedule the ISC2 exam
- Access to community and mentor support after the course ends