ISACA Certification

CISM

Certified Information Security Manager

ISACA | 4 domains · 47 lessons and reviews | Free Preview

This track is built to help you think like a security manager — the way ISACA expects on the CISM exam. Not memorization. Not checklists. Decision-driven reasoning across governance, risk, program management, and incident response.

Exam Update Notice: ISACA’s 2026 job-practice update confirms that the active 2022 CISM outline remains in effect through November 2, 2026. The revised CISM exam begins November 3, 2026, with domain weights of 18% / 20% / 33% / 29%. ISACA’s updated preparation materials begin September 1, 2026. This track does not yet cover the revised outline.

Exam Details

CISM exam details
Detail CISM
Format 150 multiple-choice questions
Time 4 hours
Standard Exam Fee (USD; verify current price) $575 USD (ISACA member) / $760 USD (non-member)
Passing Score 450 out of 800
Experience 5 years of professional information security management experience, earned within the 10 years before applying and spanning at least 3 of the 4 CISM domains. You may pass the exam first but must apply within 5 years
Renewal 120 CPE hours per 3-year cycle, with at least 20 each year; annual fee $45 (member) / $85 (non-member)

Source and Scope Note

Track scope checked August 29, 2026. The reference was ISACA’s current CISM Examination Content Outline (Effective 2022), which launched on June 1, 2022 and remains active through November 2, 2026. The revised exam begins November 3, 2026; until this track is updated, it covers only the active 2022 outline.

This note records the outline used for the track; it does not mean ISACA reviewed or endorsed the lessons. The practice material is original and does not reproduce live exam items. Report a content issue.

What You’ll Learn

  • Understand information security governance from a management perspective
  • Build decision frameworks for risk management scenarios under uncertainty
  • Learn what ISACA expects when evaluating security programs and incident response
  • Use reading, practice, and domain evidence to choose what to review next
Start a Free Lesson →
Domain 1 — Information Security Governance (17%)

Enterprise governance, organizational culture, legal and regulatory requirements, and information security strategy development.

Section A — Enterprise Governance

  1. 1 Organizational Culture Free Free Preview
  2. 2 Legal, Regulatory, and Contractual Requirements Full Access
  3. 3 Organizational Structures, Roles, and Responsibilities Full Access
  4. Section A Review: Enterprise Governance Full Access

Section B — Information Security Strategy

  1. 4 Information Security Strategy Development Full Access
  2. 5 Information Governance Frameworks and Standards Full Access
  3. 6 Strategic Planning Full Access
  4. Section B Review: Information Security Strategy Full Access

Domain 1 Review

  1. Capstone Review: INFORMATION SECURITY GOVERNANCE Full Access
Domain 2 — Information Security Risk Management (20%)

Risk identification, assessment, response, and monitoring aligned to organizational objectives and risk appetite.

Section A — Information Security Risk Assessment

  1. 7 Emerging Risk and Threat Landscape Free Free Preview
  2. 8 Vulnerability and Control Deficiency Analysis Full Access
  3. 9 Risk Assessment and Analysis Full Access
  4. Section A Review: Information Security Risk Assessment Full Access

Section B — Information Security Risk Response

  1. 10 Risk Treatment / Risk Response Options Full Access
  2. 11 Risk and Control Ownership Full Access
  3. 12 Risk Monitoring and Reporting Full Access
  4. Section B Review: Information Security Risk Response Full Access

Domain 2 Review

  1. Capstone Review: INFORMATION SECURITY RISK MANAGEMENT Full Access
Domain 3 — Information Security Program (33%)

Program development, resource management, control design and implementation, awareness training, and external service management.

Section A — Information Security Program Development

  1. 13 Information Security Program Resources Free Free Preview
  2. 14 Information Asset Identification and Classification Full Access
  3. 15 Industry Standards and Frameworks for Information Security Full Access
  4. 16 Information Security Policies, Procedures, and Guidelines Full Access
  5. 17 Information Security Program Metrics Full Access
  6. Section A Review: Information Security Program Development Full Access

Section B — Information Security Program Management

  1. 18 Information Security Control Design and Selection Full Access
  2. 19 Information Security Control Implementation and Integrations Full Access
  3. 20 Information Security Control Testing and Evaluation Full Access
  4. 21 Information Security Awareness and Training Full Access
  5. 22 Management of External Services Full Access
  6. 23 Information Security Program Communications and Reporting Full Access
  7. Section B Review: Information Security Program Management Full Access

Domain 3 Review

  1. Capstone Review: INFORMATION SECURITY PROGRAM Full Access
Domain 4 — Incident Management (30%)

Incident management readiness, response planning, business continuity, disaster recovery, and post-incident review.

Section A — Incident Management Readiness

  1. 24 Incident Response Plan Free Free Preview
  2. 25 Business Impact Analysis (BIA) Full Access
  3. 26 Business Continuity Plan (BCP) Full Access
  4. 27 Disaster Recovery Plan (DRP) Full Access
  5. 28 Incident Classification/Categorization Full Access
  6. 29 Incident Management Training, Testing, and Evaluation Full Access
  7. Section A Review: Incident Management Readiness Full Access

Section B — Incident Management Operations

  1. 30 Incident Management Tools and Techniques Full Access
  2. 31 Incident Investigation and Evaluation Full Access
  3. 32 Incident Containment Methods Full Access
  4. 33 Incident Response Communications Full Access
  5. 34 Incident Eradication and Recovery Full Access
  6. 35 Post-Incident Review Practices Full Access
  7. Section B Review: Incident Management Operations Full Access

Domain 4 Review

  1. Capstone Review: INCIDENT MANAGEMENT Full Access

Career Benefits

  • Relevant to security management, program leadership, and governance roles
  • An established certification focused on information security management
  • Listed as a qualification option for certain DoD 8140 work roles; verify the current matrix for a specific position
  • May be requested or valued for security management and program-leadership roles

How It Compares

CISM focuses on managing and overseeing an enterprise’s information security program, while CRISC concentrates on IT risk and controls. CySA+ V4 (CS0-004) is the operational alternative in this set: it focuses on detecting and analyzing activity, prioritizing vulnerabilities, coordinating incident response, and communicating findings rather than managing an enterprise security program.

Security+ followed by CySA+ can support a foundation-to-analyst progression, but neither is required before CISM. Consider CISM when your documented work and goals align with governance, risk, security-program management, and incident-management oversight. See the full comparison →

Head-to-head comparisons: CRISC vs CISM · CISSP vs CISM · Security+ vs CISM