CISSP Certified Information Systems Security Professional

Level: Expert

Develop Advanced Cyber Security Leadership Skills
Master All Eight CISSP Security Domains
Prepare for the Globally Recognised ISC2 CISSP Certification
Our Exam Pass Guarantee Included*
Welsh Government Funding Accepted

Course Overview

Duration: 5 Days (9:30am-5:00pm) Accredited: Yes Exams: Included Funding: ReAct Type: Classroom, Onsite, Virtual Company group booking discount available
This intensive five-day course will help you prepare for the ISC2 Certified Information Systems Security Professional (CISSP) examination. You’ll develop the technical and managerial knowledge needed to design, implement and manage an effective cybersecurity programme. The course covers the eight domains of the CISSP Common Body of Knowledge, including risk [...]

This intensive five-day course will help you prepare for the ISC2 Certified Information Systems Security Professional (CISSP) examination.

You’ll develop the technical and managerial knowledge needed to design, implement and manage an effective cybersecurity programme. The course covers the eight domains of the CISSP Common Body of Knowledge, including risk management, asset security, security architecture, network security, identity and access management, security testing, operations and software development security.

You’ll review important concepts, consider how they apply to real organisational situations and develop the broad understanding required for the CISSP examination.

Target Audience

This course is suitable for:

  • Chief information security officers
  • Security directors and managers
  • IT directors and managers
  • Security architects and consultants
  • Security engineers and analysts
  • Security auditors
  • Network architects
  • Experienced cybersecurity professionals preparing for the CISSP examination

By the End of This Course, You Will Be Able To

  • Apply security governance and risk management principles.
  • Protect information and organisational assets throughout their lifecycle.
  • Evaluate security architecture and engineering controls.
  • Explain secure network design and communication technologies.
  • Apply identity and access management principles.
  • Plan security assessments, testing and audits.
  • Support secure operations, incident response and disaster recovery.
  • Integrate security throughout the software development lifecycle.
  • Approach CISSP examination questions with greater confidence.
This intensive five-day course will help you prepare for the ISC2 Certified Information Systems Security Professional (CISSP) examination. You’ll develop the technical and managerial knowledge needed to design, implement and manage an effective cybersecurity programme. The course covers the eight domains of the CISSP Common Body of Knowledge, including risk [...]

This intensive five-day course will help you prepare for the ISC2 Certified Information Systems Security Professional (CISSP) examination.

You’ll develop the technical and managerial knowledge needed to design, implement and manage an effective cybersecurity programme. The course covers the eight domains of the CISSP Common Body of Knowledge, including risk management, asset security, security architecture, network security, identity and access management, security testing, operations and software development security.

You’ll review important concepts, consider how they apply to real organisational situations and develop the broad understanding required for the CISSP examination.

Target Audience

This course is suitable for:

  • Chief information security officers
  • Security directors and managers
  • IT directors and managers
  • Security architects and consultants
  • Security engineers and analysts
  • Security auditors
  • Network architects
  • Experienced cybersecurity professionals preparing for the CISSP examination

By the End of This Course, You Will Be Able To

  • Apply security governance and risk management principles.
  • Protect information and organisational assets throughout their lifecycle.
  • Evaluate security architecture and engineering controls.
  • Explain secure network design and communication technologies.
  • Apply identity and access management principles.
  • Plan security assessments, testing and audits.
  • Support secure operations, incident response and disaster recovery.
  • Integrate security throughout the software development lifecycle.
  • Approach CISSP examination questions with greater confidence.

CISSP Certified Information Systems Security Professional

Module 1. Security and Risk Management

Aligning security and risk to organisational objectives

  • Evaluate and apply security governance principles
  • Implement policies, standards and procedures
  • Applying compliance

Applying risk management concepts

  • Assessing threats and vulnerabilities
  • Performing risk analysis and control
  • Defining qualitative and quantitative analysis

Preserving the business

  • Adhering to Business Continuity Management Code of Practise and Specifications
  • Performing a business impact analysis

Investigating legal measures and techniques

  • Reviewing intellectual property, liability and law, and compliance
  • Differentiating traditional computer crime
  • Establishing information and asset handling requirements

Module 2. Asset Security

Examining security models and frameworks

  • The Information Security Triad and multi-level models
  • Investigating industry standards: ISO 27001/27002
  • Evaluating security model fundamental concepts

Exploring system and component security concepts

  • Certification and accreditation criteria and models
  • Reviewing mobile system/cloud/IoT vulnerabilities

Protecting information by applying cryptography

  • Detailing symmetric and asymmetric encryption systems
  • Ensuring message integrity through hashing
  • Uncovering threats to cryptographic systems

Safeguarding physical resources

  • Designing environments to resist hostile acts and threats
  • Designing environments to resist hostile acts and threats

Module 3. Communication & Network Security

Defining a secure network architecture

  • TCP/IP and other protocol models
  • Protecting from network attacks
  • Reviewing secure network components and communication channels

Examining secure networks and components

  • Identifying wired and wireless technologies
  • Implementing firewalls, secure communications, proxies, and tunnels

Module 4. Identity & Access Management

Controlling access to protect assets

  • Defining administrative, technical and physical controls
  • Implementing centralised and decentralised approaches
  • Investigating biometric and multi-factor authentication
  • Identifying common threats
  • Managing the identity and access provisioning lifecycle

Module 6. Security Assessment & Testing

Designing and conducting security assessment strategies

  • Leveraging the role of testing and auditing to analyse the effectiveness of security controls
  • Differentiating detection and protection systems

Conducting logging and monitoring activities

  • Distinguishing between the roles of internal and external audits
  • Conduct or facilitate security audits

Module 7. Security Operations

Maintaining operational resilience

  • Managing security services effectively
  • Leveraging and supporting investigations and incident response
  • Differentiating detection and protection systems
  • Securely provisioning resources

Developing a recovery strategy

  • Designing a disaster recovery plan
  • Implementing test and maintenance processes
  • Provisioning of resources

Module 8. Software Security Development

Securing the software development life cycle

  • Applying software development methods and security controls
  • Addressing database security concepts and issues
  • Define and apply secure coding guidelines and standards
  • Reviewing software security effectiveness and security impact

CISSP Certified Information Systems Security Professional

Module 1. Security and Risk Management

Aligning security and risk to organisational objectives

  • Evaluate and apply security governance principles
  • Implement policies, standards and procedures
  • Applying compliance

Applying risk management concepts

  • Assessing threats and vulnerabilities
  • Performing risk analysis and control
  • Defining qualitative and quantitative analysis

Preserving the business

  • Adhering to Business Continuity Management Code of Practise and Specifications
  • Performing a business impact analysis

Investigating legal measures and techniques

  • Reviewing intellectual property, liability and law, and compliance
  • Differentiating traditional computer crime
  • Establishing information and asset handling requirements

Module 2. Asset Security

Examining security models and frameworks

  • The Information Security Triad and multi-level models
  • Investigating industry standards: ISO 27001/27002
  • Evaluating security model fundamental concepts

Exploring system and component security concepts

  • Certification and accreditation criteria and models
  • Reviewing mobile system/cloud/IoT vulnerabilities

Protecting information by applying cryptography

  • Detailing symmetric and asymmetric encryption systems
  • Ensuring message integrity through hashing
  • Uncovering threats to cryptographic systems

Safeguarding physical resources

  • Designing environments to resist hostile acts and threats
  • Designing environments to resist hostile acts and threats

Module 3. Communication & Network Security

Defining a secure network architecture

  • TCP/IP and other protocol models
  • Protecting from network attacks
  • Reviewing secure network components and communication channels

Examining secure networks and components

  • Identifying wired and wireless technologies
  • Implementing firewalls, secure communications, proxies, and tunnels

Module 4. Identity & Access Management

Controlling access to protect assets

  • Defining administrative, technical and physical controls
  • Implementing centralised and decentralised approaches
  • Investigating biometric and multi-factor authentication
  • Identifying common threats
  • Managing the identity and access provisioning lifecycle

Module 6. Security Assessment & Testing

Designing and conducting security assessment strategies

  • Leveraging the role of testing and auditing to analyse the effectiveness of security controls
  • Differentiating detection and protection systems

Conducting logging and monitoring activities

  • Distinguishing between the roles of internal and external audits
  • Conduct or facilitate security audits

Module 7. Security Operations

Maintaining operational resilience

  • Managing security services effectively
  • Leveraging and supporting investigations and incident response
  • Differentiating detection and protection systems
  • Securely provisioning resources

Developing a recovery strategy

  • Designing a disaster recovery plan
  • Implementing test and maintenance processes
  • Provisioning of resources

Module 8. Software Security Development

Securing the software development life cycle

  • Applying software development methods and security controls
  • Addressing database security concepts and issues
  • Define and apply secure coding guidelines and standards
  • Reviewing software security effectiveness and security impact
  • Examination: Certified Information Systems Security Professional
  • Awarding body: ISC2
  • Delivery method: Computerised Adaptive Testing
  • Duration: Three hours
  • Number of questions: Between 100 and 150
  • Question format: Multiple-choice and advanced item types
  • Passing score: 700 out of 1,000
  • Delivery: ISC2-authorised Pearson VUE testing centre
  • Examination voucher: Not included

Certification Requirements

To become CISSP certified, you must have at least five years of cumulative professional experience in two or more of the eight CISSP domains.

A relevant degree or an additional credential from ISC2’s approved list may satisfy up to one year of the experience requirement. Only one year can be waived.

You must also:

  • Pass the CISSP examination.
  • Complete the ISC2 endorsement process.
  • Agree to follow the ISC2 Code of Ethics.
  • Pay the applicable annual maintenance fee.
  • Meet ISC2’s continuing professional education requirements.

If you pass the examination without the required experience, you can become an Associate of ISC2 while working towards full certification. You will then have six years to obtain the required five years of experience.

  • Examination: Certified Information Systems Security Professional
  • Awarding body: ISC2
  • Delivery method: Computerised Adaptive Testing
  • Duration: Three hours
  • Number of questions: Between 100 and 150
  • Question format: Multiple-choice and advanced item types
  • Passing score: 700 out of 1,000
  • Delivery: ISC2-authorised Pearson VUE testing centre
  • Examination voucher: Not included

Certification Requirements

To become CISSP certified, you must have at least five years of cumulative professional experience in two or more of the eight CISSP domains.

A relevant degree or an additional credential from ISC2’s approved list may satisfy up to one year of the experience requirement. Only one year can be waived.

You must also:

  • Pass the CISSP examination.
  • Complete the ISC2 endorsement process.
  • Agree to follow the ISC2 Code of Ethics.
  • Pay the applicable annual maintenance fee.
  • Meet ISC2’s continuing professional education requirements.

If you pass the examination without the required experience, you can become an Associate of ISC2 while working towards full certification. You will then have six years to obtain the required five years of experience.

  • Five days of instructor-led training and examination preparation delivered by an experienced CISSP trainer.
  • Course notes and presentation slides.
  • Exam Pass Guarantee – if you do not pass the examination after attending the course, you can retake the same training with NILC at no additional cost. You will only need to pay the examination fee charged by ISC2.

Please note: The official CISSP examination voucher is not included in the course price. You must register and pay for the examination separately.

  • Five days of instructor-led training and examination preparation delivered by an experienced CISSP trainer.
  • Course notes and presentation slides.
  • Exam Pass Guarantee – if you do not pass the examination after attending the course, you can retake the same training with NILC at no additional cost. You will only need to pay the examination fee charged by ISC2.

Please note: The official CISSP examination voucher is not included in the course price. You must register and pay for the examination separately.

There are no formal prerequisites for attending this course or sitting the CISSP examination.

However, CISSP is intended for experienced cybersecurity practitioners, managers and executives. You should have a broad understanding of information security and practical experience in one or more cybersecurity disciplines.

Passing the examination does not automatically make you CISSP certified. You must also meet ISC2’s professional experience, endorsement and membership requirements.

There are no formal prerequisites for attending this course or sitting the CISSP examination.

However, CISSP is intended for experienced cybersecurity practitioners, managers and executives. You should have a broad understanding of information security and practical experience in one or more cybersecurity disciplines.

Passing the examination does not automatically make you CISSP certified. You must also meet ISC2’s professional experience, endorsement and membership requirements.

Does this course include an Exam Pass Guarantee?

Yes. If you do not pass after attending our course, you can repeat the same training with us free of charge. You will need to pay the examination fee charged by the examination provider.

Who is the CISSP course suitable for?

Our course is designed for experienced cybersecurity practitioners, managers and leaders. It is particularly relevant to security managers, consultants, architects, analysts, auditors and professionals responsible for designing, implementing or managing an organisation’s security programme.

Do I need cybersecurity experience to attend?

This is an expert-level, accelerated exam-preparation course, so substantial professional security knowledge is strongly recommended.

To gain full CISSP certification, you normally need five years of cumulative paid experience across at least two CISSP domains. An approved degree or credential may waive one year. You may still take the exam without the required experience and work towards becoming an ISC2 member as an Associate.

View all FAQs

Does this course include an Exam Pass Guarantee?

Yes. If you do not pass after attending our course, you can repeat the same training with us free of charge. You will need to pay the examination fee charged by the examination provider.

Who is the CISSP course suitable for?

Our course is designed for experienced cybersecurity practitioners, managers and leaders. It is particularly relevant to security managers, consultants, architects, analysts, auditors and professionals responsible for designing, implementing or managing an organisation’s security programme.

Do I need cybersecurity experience to attend?

This is an expert-level, accelerated exam-preparation course, so substantial professional security knowledge is strongly recommended.

To gain full CISSP certification, you normally need five years of cumulative paid experience across at least two CISSP domains. An approved degree or credential may waive one year. You may still take the exam without the required experience and work towards becoming an ISC2 member as an Associate.

View all FAQs

Dates & Prices

Upcoming Courses
Live Instructor-Led Virtual
Spaces: Available Start Date: Mon 28 September 2026
£2,750.00 excl. VAT
Live Instructor-Led Virtual
Spaces: Available Start Date: Mon 26 October 2026
£2,750.00 excl. VAT
Live Instructor-Led Virtual
Spaces: Available Start Date: Mon 14 December 2026
£2,750.00 excl. VAT

Can't find the course dates, location or delivery type you are looking for?

Fill out the request dates form above and we'll try our best to accommodate or contact us directly.

"*" indicates required fields

Name*
Number of Delegates*
Course Delivery Format*

How we deliver our courses

Virtual

Our virtual courses allow you to access live instructor-led training from the same expert instructors that deliver our classroom courses, without leaving the comfort of your home or office. All virtual courses are fully interactive, and learners can communicate with their trainer and peers at any time.

Many of our virtual courses are also recorded, so you can recap over the content you learnt as many time as you wish.

Find out more about Virtual learning

Classroom

Our classroom courses allow you to learn and interact face-to-face with our expert instructors in a comfortable and modern training environment. All of our classroom based courses take place at NILC centers, or high quality training facilities, and include all required IT and physical equipment.

We also limit our class sizes to help promote better discussions and to ensure your learning experience is comfortable as possible.

Find out more about Classroom learning

Onsite

Save time and hassle by arranging for one of our expert instructors to come to you. Our onsite courses allow you to learn in a location of your choosing, and you can train as many or as few people as you want – from a single person or team to whole departments. We can also fully customize the course content to the specific requirements of your business or project.

We offer onsite courses throughout the UK and it can be a great team building opportunity for colleagues to come together, bond and discuss.

Find out more about Onsite learning

Online

Our Online Self Paced courses allow you to learn new skills from our expert instructors, in your own time and at your own pace. Our flexible online learning platform allows you to access content on your computer, tablet or mobile device, whether you’re on the move or at home. All our online courses come with immediate access and you can start learning straight away, from any internet enabled compatible device.

We also offer online email support from our expert instructors, so they’re always on hand and happy to help you with any questions which may arise.

Find out more about Online learning

Why choose NILC for your training?

Award-Winning Training with Industry-Leading Customer Satisfaction

Trusted Training Partner by Colleges, Government Organisations and Businesses

UK-Based Trainers with Real-World Industry Experience

Family-Run Business with Customer Service at Its Core

Rated Excellent on Trustpilot with 950+ Customer Reviews

Our learners rate us 'Excellent' on Trustpilot

Frequently Asked Questions

Yes. If you do not pass after attending our course, you can repeat the same training with us free of charge. You will need to pay the examination fee charged by the examination provider.

Our course is designed for experienced cybersecurity practitioners, managers and leaders. It is particularly relevant to security managers, consultants, architects, analysts, auditors and professionals responsible for designing, implementing or managing an organisation’s security programme.

This is an expert-level, accelerated exam-preparation course, so substantial professional security knowledge is strongly recommended.

To gain full CISSP certification, you normally need five years of cumulative paid experience across at least two CISSP domains. An approved degree or credential may waive one year. You may still take the exam without the required experience and work towards becoming an ISC2 member as an Associate.

We prepare you for all eight CISSP domains:

  • Security and Risk Management
  • Asset Security
  • Security Architecture and Engineering
  • Communication and Network Security
  • Identity and Access Management
  • Security Assessment and Testing
  • Security Operations
  • Software Development Security

CISSP covers both technical and managerial security responsibilities. It examines how security programmes are designed, implemented, and managed, covering areas such as architecture, networks, identity, testing, operations, and secure software development.

Yes. CISSP covers a broad body of knowledge, and our five-day course is intensive. We recommend reviewing your course materials, practising exam-style questions and addressing weaker domains before attempting the examination.

No. Passing the exam is only part of the certification process. You must also satisfy ISC2’s professional experience requirements and complete its endorsement process.

If you pass without having enough experience, you can become an Associate of ISC2 while working towards the experience required for full certification.

Frequently Asked Questions

Yes. If you do not pass after attending our course, you can repeat the same training with us free of charge. You will need to pay the examination fee charged by the examination provider.

Our course is designed for experienced cybersecurity practitioners, managers and leaders. It is particularly relevant to security managers, consultants, architects, analysts, auditors and professionals responsible for designing, implementing or managing an organisation’s security programme.

This is an expert-level, accelerated exam-preparation course, so substantial professional security knowledge is strongly recommended.

To gain full CISSP certification, you normally need five years of cumulative paid experience across at least two CISSP domains. An approved degree or credential may waive one year. You may still take the exam without the required experience and work towards becoming an ISC2 member as an Associate.

We prepare you for all eight CISSP domains:

  • Security and Risk Management
  • Asset Security
  • Security Architecture and Engineering
  • Communication and Network Security
  • Identity and Access Management
  • Security Assessment and Testing
  • Security Operations
  • Software Development Security

CISSP covers both technical and managerial security responsibilities. It examines how security programmes are designed, implemented, and managed, covering areas such as architecture, networks, identity, testing, operations, and secure software development.

Yes. CISSP covers a broad body of knowledge, and our five-day course is intensive. We recommend reviewing your course materials, practising exam-style questions and addressing weaker domains before attempting the examination.

No. Passing the exam is only part of the certification process. You must also satisfy ISC2’s professional experience requirements and complete its endorsement process.

If you pass without having enough experience, you can become an Associate of ISC2 while working towards the experience required for full certification.

Trusted By

0