← Certifications

CSEC · Professional

Certified Security Practitioner

Validating hands-on mastery of modern cyber defense aligned to US federal guidance

Questions

29 multiple choice

Duration

75 minutes

Pass mark

80%

Fee

$35 per attempt

About this certification

The Certified Security Practitioner (CSEC) credential, offered by the American Computer Society, is designed for practitioners who must design, defend, and audit modern enterprise environments against sophisticated adversaries. It emphasizes applied competence rather than rote memorization, requiring candidates to reason through realistic scenarios involving adversary tradecraft, architectural tradeoffs, and compliance obligations. CSEC holders are expected to bridge the gap between security engineering, operations, and risk management, making the credential relevant to mid-career analysts, engineers, and architects across public and private sector environments.

A central pillar of the CSEC body of knowledge is threat modeling and secure architecture, including the practical application of zero trust principles as codified in NIST SP 800-207. Candidates learn to decompose systems using methodologies such as STRIDE and PASTA, map adversary behavior to the MITRE ATT&CK framework, and translate threat intelligence into concrete architectural controls. This domain also covers segmentation strategies, software-defined perimeters, and the shift away from implicit trust models toward continuous verification of users, devices, and workloads.

Identity and access management receives significant emphasis, reflecting its role as the modern security perimeter. The exam addresses federated identity, multi-factor authentication, privileged access management, and the operational nuances of implementing least privilege at scale. Candidates must also demonstrate applied cryptography knowledge, including key management lifecycles, PKI design, transport and data-at-rest protections, and the practical implications of emerging post-quantum cryptography guidance from NIST.

Detection and incident response form another core competency area, requiring familiarity with SIEM and SOAR tooling, log correlation, threat hunting methodologies, and structured incident response following NIST SP 800-61 guidance. Candidates are tested on their ability to triage alerts, scope incidents, coordinate containment and eradication, and produce actionable post-incident reports that feed back into organizational risk posture and control tuning.

Governance, risk, and compliance rounds out the credential, with heavy alignment to NIST Cybersecurity Framework 2.0, NIST SP 800-53 control families, FedRAMP authorization processes, and binding operational directives issued by CISA. Candidates must understand how to map technical controls to compliance obligations, conduct risk assessments, and communicate residual risk to executive stakeholders in a manner consistent with federal and regulated-industry expectations.

Overall, CSEC is positioned as a rigorous, scenario-driven credential that certifies a practitioner's ability to operate across the full security lifecycle — from architecture and identity through detection, response, and governance — within the specific regulatory and doctrinal context that shapes United States federal and critical infrastructure cybersecurity practice.

Syllabus and exam weighting

Threat Modeling and Secure Architecture

18%

Covers structured approaches to identifying and mitigating design-level security weaknesses. Candidates learn to apply threat modeling frameworks and translate adversary tradecraft into architectural decisions, including zero trust design principles.

  • ▪STRIDE and PASTA threat modeling methodologies
  • ▪MITRE ATT&CK mapping to architectural controls
  • ▪NIST SP 800-207 zero trust architecture tenets
  • ▪Microsegmentation and software-defined perimeters
  • ▪Secure design patterns for hybrid and multi-cloud environments
  • ▪Attack surface reduction and defense-in-depth
  • ▪Data flow diagrams and trust boundary analysis
  • ▪Secure SDLC integration of threat modeling

Identity and Access Management

16%

Focuses on the design and operation of identity-centric controls that enforce least privilege across users, devices, and workloads. Includes federation, authentication assurance, and privileged access governance.

  • ▪Federated identity and SAML/OIDC protocols
  • ▪Multi-factor and passwordless authentication
  • ▪Privileged access management and just-in-time access
  • ▪Role-based and attribute-based access control
  • ▪Continuous authentication and device trust signals
  • ▪Identity governance and lifecycle management
  • ▪Service and machine identity management

Applied Cryptography

15%

Examines cryptographic mechanisms used to protect data confidentiality, integrity, and authenticity across systems. Emphasis is placed on operational key management and emerging post-quantum considerations.

  • ▪Symmetric and asymmetric encryption use cases
  • ▪Public key infrastructure design and certificate lifecycle
  • ▪Key management systems and hardware security modules
  • ▪Transport layer security configuration and pitfalls
  • ▪Data-at-rest encryption strategies
  • ▪Hashing, digital signatures, and message authentication codes
  • ▪NIST post-quantum cryptography standardization and migration planning

Detection Engineering and Incident Response

20%

Covers the operational skills required to detect, triage, and respond to security incidents. Includes tooling, threat hunting, and structured response processes aligned to NIST incident handling guidance.

  • ▪SIEM architecture, log correlation, and alert tuning
  • ▪SOAR playbook design and automation
  • ▪Threat hunting hypotheses and methodologies
  • ▪NIST SP 800-61 incident response lifecycle
  • ▪Digital forensics fundamentals and chain of custody
  • ▪Malware analysis basics and indicators of compromise
  • ▪Post-incident reporting and lessons-learned processes
  • ▪Tabletop exercises and incident response plan validation

Governance, Risk, and Compliance

17%

Addresses the frameworks and processes used to manage organizational cybersecurity risk and demonstrate regulatory compliance. Strong emphasis on NIST and federal guidance relevant to US government and contractor environments.

  • ▪NIST Cybersecurity Framework 2.0 functions and profiles
  • ▪NIST SP 800-53 control families and control selection
  • ▪FedRAMP authorization process and continuous monitoring
  • ▪CISA binding operational directives and emergency directives
  • ▪Risk assessment methodologies and risk registers
  • ▪Third-party and supply chain risk management
  • ▪Security policy development and executive risk communication

Security Operations and Resilience

14%

Focuses on sustaining security posture through operational practices including vulnerability management, business continuity, and resilience engineering across on-premises and cloud environments.

  • ▪Vulnerability management and patch prioritization
  • ▪Business continuity and disaster recovery planning
  • ▪Cloud security posture management
  • ▪Configuration management and hardening baselines
  • ▪Security awareness and insider threat programs
  • ▪Metrics, KPIs, and security program maturity models

Learning outcomes

  • ✓Design and evaluate zero trust architectures consistent with NIST SP 800-207 for enterprise and hybrid cloud environments
  • ✓Apply structured threat modeling methodologies to identify, prioritize, and mitigate architectural risks
  • ✓Implement identity and access management controls including federation, MFA, and privileged access governance
  • ✓Select and apply appropriate cryptographic controls across data lifecycle states, including key management and PKI operations
  • ✓Lead detection and incident response activities using SIEM/SOAR tooling aligned to NIST SP 800-61 incident handling guidance
  • ✓Map technical security controls to NIST SP 800-53 control families and communicate compliance posture within FedRAMP and CISA directive contexts

Exam format

Delivery
Online proctored exam delivered via secure browser with live remote proctoring; also available at authorized testing centers.
Retakes
A $35 fee applies per attempt. Candidates must wait 14 days between attempts and are limited to a maximum of 3 attempts within any 12-month period.
Pass mark
80% of 29 scored questions. Results are graded instantly in MyACS with a domain-by-domain breakdown.

Maintaining the credential

  • ▪CSEC certification is valid for 3 years from the date of issuance
  • ▪Certified professionals must earn 60 Continuing Professional Development (CPD) hours within the 3-year cycle
  • ▪At least 20 CPD hours must be earned through hands-on technical training, labs, or applied workshops
  • ▪Certificants must submit an annual ethics attestation affirming adherence to the ACS Code of Professional Conduct
  • ▪Recertification may alternatively be achieved by retaking and passing the current version of the CSEC examination

Recommended reading

NIST Special Publication 800-207: Zero Trust Architecture

National Institute of Standards and Technology

The foundational federal reference for zero trust design principles and implementation models covered extensively in the architecture domain.

NIST Special Publication 800-53 Revision 5: Security and Privacy Controls

National Institute of Standards and Technology

The definitive control catalog underpinning federal risk management and FedRAMP authorization, essential for the governance domain.

Applied Cryptography: Protocols, Algorithms, and Source Code in C

Wiley

A technically rigorous reference for cryptographic primitives and protocol design relevant to the applied cryptography domain.

Incident Response & Computer Forensics

McGraw-Hill Education

A practitioner-oriented guide to incident handling, forensics, and evidence management aligned with NIST SP 800-61 processes.