ISSMP
Information Systems Security Management Professional
ISC2 specialization for security management. Requires CISSP. Focus on Leadership, Risk Management, Security Operations, and Compliance Management. For CISOs and senior security executives.
› Quality score
Four-axis SecProve rubric, each 0–10. SecProve editorial assessment — each axis carries a written justification so you can push back on any single call without dismissing the whole score.
› Market signals
public, citable inputs to the recognition score› Built for these roles
› Exam format
Linear, 125 questions, 3 hours, 700/1000
30/60/90 day waits for retakes 1/2/3 in a rolling 12-month window.
› Recertification
60-140 CPEs per 3-year cycle, $135/year AMF
› 3-year cost of ownership
Excludes study materials, training, retake risk, and lost-wage opportunity. Use as a floor estimate.
› NICE Framework work roles
The NIST NICE work-role IDs this cert maps to. NICCS lookup.
› Core domains covered
The 3 domains this cert is centrally about. Passing the exam demonstrates working knowledge of each.
Cyber risk quantification, board communication, security program development, budget & ROI.
Risk frameworks (NIST RMF, ISO 31000, FAIR), policy development, audit, regulatory compliance, third-party risk.
IR playbooks, memory/disk/network forensics, chain of custody, malware analysis.
› Prerequisites
Active CISSP + 2 years experience in the respective specialization
› Progression
requiredrecommendedWhere this cert fits in the typical learning path. Required edges are vendor-gated; recommended edges reflect de facto industry progression.
No de facto priors typically expected.
No certs require this one.
No follow-on certs reference this one yet.
› Study materials
Curated starting points. Not exhaustive — vet each against your learning style and the current exam version.
- Official (ISC)² ISSMP CBK Reference — Wiley/ISC2
- Boson ExSim-Max for ISSMP
› Version & lifecycle
› Salary signal
Senior security manager / director, US, 7+ years. Requires active CISSP.
Robert Half Salary Guide + Glassdoor 'Security Manager' aggregations · 2024 · US base only · p25–p75 range
› How it compares
ISSMP is the ISC2 management concentration; CISM is the standalone ISACA equivalent — both target the same role.
↔ Compare side-by-side› Careers that commonly pursue this cert
Lead security strategy, communicate risk to the board, and build security programs. Executive-level cybersecurity leadership.
See this cert’s domains highlighted on the interactive map, or compare it against the rest of the catalog.