ISACA Certification Exam Prep
Study guides, practice exams, and flashcards for all ISACA certifications. 1 certification available.
About CISM Certification
The CISM (Certified Information Security Manager) is ISACA's credential for information security professionals who manage, design, and oversee an enterprise's security program — distinct from CISSP's broader technical-and-managerial scope, CISM is built specifically around the security manager role: governance, risk, program development, and incident response, not hands-on control implementation.
The exam covers four domains: Information Security Governance (17%), Information Security Risk Management (20%), Information Security Program (33%), and Incident Management (30%). It runs 150 multiple-choice questions over 4 hours, scored on a scaled 200–800 range with 450 required to pass — not a flat percentage, since item difficulty is weighted.
Eligibility requires 5 years of cumulative information security management work experience (some substitutions and waivers apply), though candidates can sit the exam itself before that experience is fully verified. CISM is almost entirely scenario-based — most questions describe a situation and ask for the MOST appropriate, BEST, or FIRST action a security manager would take.
Career value: CISM is one of the most requested credentials for CISO, IT security manager, and security program director postings, and it signals the shift from hands-on security work to managing security as a business function. Candidates who reason like the person accountable for organizational risk — not the person configuring the firewall — do best on this exam.
All ISACA Certifications
Advanced
[CISM] Certified Information Security Manager
The premier certification for information security managers who bridge security and business strategy.
Recommended Learning Paths
Security Management Path
Key Topic Areas
The core domains tested across ISACA certifications. Each badge links to the study guide for an exam that covers the area.
Information Security Governance
Security strategy and business alignment · Governance frameworks and standards · Roles, responsibilities and reporting lines · Organizational culture · Legal, regulatory and contractual requirements · Building the security business case
Information Security Risk Management
Risk identification and assessment · Risk analysis and evaluation · Risk treatment and response options · Risk appetite and tolerance · Third-party and supply-chain risk · Risk monitoring, reporting and registers
Information Security Program
Program resources and roadmap · Asset classification and ownership · Control design, selection and implementation · Security standards and frameworks · Awareness and training · Metrics, KPIs and management reporting · Vendor and service-provider management
Incident Management
Incident response planning and playbooks · Classification, triage and escalation · Containment, eradication and recovery · Business continuity and disaster recovery · Digital forensics and evidence handling · Post-incident review and testing
Frequently Asked Questions
Explore More Certifications
Browse all certification paths across AWS, Azure, CompTIA, and more.
Browse All Certifications