EVIDENCE · NOT SCORES
SIGN IN
← ALL CERTIFICATIONS

ISC2

Systems Security Certified Practitioner

SYSTEMS SECURITY CERTIFIED PRACTITIONEREXAM SSCPBLUEPRINT SSCP-OCTOBER-2025

BUILD MY CERTIFICATION PATH

EXAM BLUEPRINT

The published domains and objectives for SSCP. Your missions come from these objectives, and your progress is recorded against them.

  • 16%

    1

    Security Concepts and Practices

    • 1.1Comply with codes of ethics
    • 1.2Understand security concepts
    • 1.3Identify and implement security controls
    • 1.4Document and maintain functional security controls
    • 1.5Support and implement asset management lifecycle (i.e., hardware, software, and data)
    • 1.6Support and/or implement change management lifecycle
    • 1.7Support and/or implement security awareness and training (e.g., social engineering/phishing/tabletop exercises/awareness communications)
    • 1.8Collaborate with physical security operations (e.g., data center/facility assessment, badging and visitor management, personal device restrictions)
  • 15%

    2

    Access Controls

    • 2.1Implement and maintain authentication methods
    • 2.2Understand and support internetwork trust architectures
    • 2.3Support and/or implement the identity management lifecycle
    • 2.4Understand and administer access controls
  • 15%

    3

    Risk Identification, Monitoring and Analysis

    • 3.1Understand risk management
    • 3.2Understand legal and regulatory concerns (e.g., jurisdiction, limitations, privacy)
    • 3.3Perform security assessments and vulnerability management activities
    • 3.4Operate and monitor security platforms (e.g., continuous monitoring)
    • 3.5Analyze monitoring results
  • 14%

    4

    Incident Response and Recovery

    • 4.1Understand and support incident response lifecycle (e.g., National Institute of Standards and Technology (NIST), International Organization for Standardization (ISO))
    • 4.2Understand and support forensic investigations
    • 4.3Understand and support business continuity plan (BCP) and disaster recovery plan (DRP)
  • 9%

    5

    Cryptography

    • 5.1Understand reasons and requirements for cryptography
    • 5.2Apply cryptography concepts
    • 5.3Understand and implement secure protocols
    • 5.4Understand public key infrastructure (PKI)
  • 16%

    6

    Network and Communications Security

    • 6.1Understand and apply fundamental concepts of networking
    • 6.2Understand network attacks (e.g., distributed denial of service (DDoS), man-in-the-middle (MITM), Domain Name System (DNS) cache poisoning)
    • 6.3Manage network access controls
    • 6.4Manage network security
    • 6.5Operate and configure network-based security appliances and services
    • 6.6Secure wireless communications
    • 6.7Secure and monitor Internet of Things (IoT)
  • 15%

    7

    Systems and Application Security

    • 7.1Identify and analyze malicious code and activity
    • 7.2Implement and operate endpoint device security
    • 7.3Administer and manage mobile devices
    • 7.4Understand and configure cloud security
    • 7.5Operate and maintain secure virtual environments