ISC ISSEP 認定試験の出題範囲:
| トピック | 出題範囲 |
|---|
| トピック 1 | - Systems Security Implementation, Verification and Validation: This domain covers the hands-on implementation and integration of security solutions into systems, including the development of security test plans and the verification, validation, and stakeholder acceptance of the implemented security.
|
| トピック 2 | - Risk Management: This domain addresses how to apply security risk management principles in alignment with enterprise risk management, covering the full lifecycle of identifying, analyzing, evaluating, monitoring, and documenting risks at both the system and operational levels.
|
| トピック 3 | - Security Planning and Engineering: This domain focuses on analyzing the organizational environment, applying system security principles such as defense-in-depth and least privilege, developing system security requirements, and translating those requirements into a validated security design.
|
| トピック 4 | - Secure Operations, Change Management and Disposal: This domain addresses planning and supporting secure system operations, managing changes through assessment and verification, and ensuring systems are securely decommissioned and disposed of in accordance with defined procedures and data retention policies.
|
| トピック 5 | - Systems Security Engineering Foundations: This domain covers the core principles, processes, and frameworks that underpin systems security engineering, including how security integrates with system development methodologies, technical management practices, procurement, and resource
- cost analysis.
|
参照:https://www.isc2.org/certifications/issep/issep-certification-exam-outline#Domain%205:%20Secure%20Operations,%20Change%20Management%20and%20Disposal
ISC ISSEP 試験概要: