This ISSEP cheat sheet distills the CISSP-ISSEP concentration exam into a condensed, printable rundown of the systems security engineering facts ISC2 tests most — from the RMF and FIPS 199 to the reference monitor and secure disposal. It's a premium cheat sheet built by Capital Prep — the one premium prep we trust — and it's yours free. Reinforce it with the rest of your free ISSEP toolkit: the practice test, study guide, and flashcards.
ISSEP exam at a glance
- Questions: 125 multiple-choice items
- Time: 3 hours (linear, fixed-form — not adaptive)
- Passing score: 700 of 1000 (scaled)
- Prerequisite: Active CISSP + 2 years' paid work in 1+ ISSEP domain
- Cost: ~$599 USD (separate from CISSP; confirm on isc2.org)
What’s on the ISSEP cheat sheet
- Systems Security Engineering Foundations (24%) — trustworthiness versus trust, the reference monitor and TCB, assurance cases, and the core security design principles.
- Security Planning and Engineering (22%) — turning protection needs into functional and assurance requirements, security architecture, cyber resiliency, and zero trust.
- Risk Management (20%) — the RMF seven steps, FIPS 199 categorization and the high-water mark, control baselines, the ATO, and the three-tier risk model.
- Implementation, Verification and Validation (20%) — verification versus validation, IV&V, vulnerability scans versus penetration tests, ST&E, and Common Criteria.
- Secure Operations, Change Management and Disposal (14%) — continuous monitoring, security impact analysis and the CCB, and NIST SP 800-88 media sanitization.
How to use it in your final week
- Lock in the RMF order cold — Prepare, Categorize, Select, Implement, Assess, Authorize, Monitor — and remember the assessor writes the SAR while the AO accepts residual risk and issues the ATO.
- Front-load the two engineering domains — Foundations (24%) and Security Planning & Engineering (22%) — which together are nearly half the exam.
- Drill the classic distinctions: verification (built it right) versus validation (built the right thing), and Clear versus Purge versus Destroy for media sanitization.
- Read the sheet the morning of your exam for a final pass on the reference monitor's three properties and FIPS 199's high-water mark, then confirm your pacing with a short timed practice set.
The cheat sheet is your review layer — your ISSEP practice test drives the exam-readiness ring at the top of this page. Download it, review, then take a full practice exam (or drill with the study guide and flashcards) to see where you stand.
ISSEP cheat sheet FAQ
Yes — the ISSEP cheat sheet is 100% free to download as a PDF, with no sign-up required. It's part of Career Employer's free CISSP-ISSEP toolkit alongside the practice test, study guide, and flashcards.
It condenses the highest-yield systems security engineering facts into a quick reference: the RMF seven steps, FIPS 199 categorization and the high-water mark, the reference monitor and TCB, security design principles, verification versus validation, and NIST SP 800-88 sanitization — organized by the five domains ISC2 weights the exam around.
It's built from ISC2's current CISSP-ISSEP exam outline and the underlying NIST publications (SP 800-160, SP 800-37, FIPS 199), and we review it against the ISC2 outline regularly.
No — the cheat sheet is a review and final-week cram aid, not a full engineering course. You need a scaled score of 700 out of 1000 to pass, so use the sheet to lock in the frameworks and the free practice test to build your readiness.
Click the download button (or the preview card) at the top of this page to open the PDF instantly. Bookmark this page so you can find it again in the final week before your CISSP-ISSEP concentration exam.
References
- 1.ISC2. “CISSP-ISSEP – Information Systems Security Engineering Professional.” isc2.org, 2026. ↑
- 2.ISC2. “CISSP-ISSEP Certification Exam Outline.” isc2.org, 2026. ↑
- 3.National Institute of Standards and Technology. “SP 800-160 Vol. 1 Rev. 1: Engineering Trustworthy Secure Systems.” csrc.nist.gov, 2022. ↑
- 4.National Institute of Standards and Technology. “SP 800-37 Rev. 2: Risk Management Framework for Information Systems and Organizations.” csrc.nist.gov, 2018. ↑
- 5.National Institute of Standards and Technology. “FIPS 199: Standards for Security Categorization of Federal Information and Information Systems.” csrc.nist.gov, 2004. ↑

Career Employer
Career Employer is the ultimate resource to help you get started working the job of your dreams. We cover topics from general career information, career searching, exam preparation with free study materials, career interviewing, and becoming successful in your career of choice.
All PostsCareer Employer’s Editorial Process
Here at Career Employer, we focus a lot on providing factually accurate information that is always up to date. We strive to provide correct information using strict editorial processes, article editing, and fact-checking for all of the information found on our website. We only utilize trustworthy and relevant resources. To find out more, make sure to read our full editorial process page here.
