Skip to main content
Career PathsOutcome → ISSO / Security Control Assessor

ISSO & Security Assessor Path

Those targeting federal information-system security roles, running the NIST RMF and assessing controls toward an authorization.

4 stepsHands-on labsCapstone + portfolioA named role

Save $297 vs. courses separately

By the end, you can

What this path makes you able to do.

  • Run the NIST Risk Management Framework end to end (SP 800-37)
  • Author SSP control implementation statements and a Security Assessment Report
  • Perform ISSO duties: categorization, POA&Ms and continuous monitoring
A guided journey, not a pile of courses

The 4-step path.

  1. 1

    Cybersecurity Foundations

    The core concepts & landscape

    View course
  2. 2

    NIST RMF Implementation

    Categorize → authorize → monitor

    View course
  3. 3

    ISSO Training

    The day-to-day ISSO role

    View course
  4. Capstone: RMF authorization package

    Categorization memo, SSP sections, SAR finding and POA&M

Practice, not just reading

Hands-on lab work.

Every step above is backed by real practice in Atlas, our simulated workbench. You do the work an employer would hand you, and you keep the artifacts as portfolio evidence.

RMF / ISSO

RMF Authorization: Meridian

Step into the ISSO seat. Take Meridian through the full Risk Management Framework lifecycle and the continuous-monitoring grind: assess controls, gather evidence, work the POA&M, and keep the authorization honest.

Every path is backed by

Hands-on labs. A final exam & capstone. A real role.

You finish with a portfolio you can show, a cumulative exam, and the skills to land the ISSO / Security Control Assessor role.

Not sure this is the one? Take the free fit and aptitude check first: twelve short questions, instant answer.