ISACA Certification Exam Prep

Study guides, practice exams, and flashcards for all ISACA certifications. 1 certification available.

About CISM Certification

The CISM (Certified Information Security Manager) is ISACA's credential for information security professionals who manage, design, and oversee an enterprise's security program — distinct from CISSP's broader technical-and-managerial scope, CISM is built specifically around the security manager role: governance, risk, program development, and incident response, not hands-on control implementation.

The exam covers four domains: Information Security Governance (17%), Information Security Risk Management (20%), Information Security Program (33%), and Incident Management (30%). It runs 150 multiple-choice questions over 4 hours, scored on a scaled 200–800 range with 450 required to pass — not a flat percentage, since item difficulty is weighted.

Eligibility requires 5 years of cumulative information security management work experience (some substitutions and waivers apply), though candidates can sit the exam itself before that experience is fully verified. CISM is almost entirely scenario-based — most questions describe a situation and ask for the MOST appropriate, BEST, or FIRST action a security manager would take.

Career value: CISM is one of the most requested credentials for CISO, IT security manager, and security program director postings, and it signals the shift from hands-on security work to managing security as a business function. Candidates who reason like the person accountable for organizational risk — not the person configuring the firewall — do best on this exam.

All ISACA Certifications

Advanced

Certified Information Security Manager logo

[CISM] Certified Information Security Manager

The premier certification for information security managers who bridge security and business strategy.

Recommended Learning Paths

Security Management Path

Key Topic Areas

The core domains tested across ISACA certifications. Each badge links to the study guide for an exam that covers the area.

Information Security Governance

Security strategy and business alignment · Governance frameworks and standards · Roles, responsibilities and reporting lines · Organizational culture · Legal, regulatory and contractual requirements · Building the security business case

Covered in:CISM

Information Security Risk Management

Risk identification and assessment · Risk analysis and evaluation · Risk treatment and response options · Risk appetite and tolerance · Third-party and supply-chain risk · Risk monitoring, reporting and registers

Covered in:CISM

Information Security Program

Program resources and roadmap · Asset classification and ownership · Control design, selection and implementation · Security standards and frameworks · Awareness and training · Metrics, KPIs and management reporting · Vendor and service-provider management

Covered in:CISM

Incident Management

Incident response planning and playbooks · Classification, triage and escalation · Containment, eradication and recovery · Business continuity and disaster recovery · Digital forensics and evidence handling · Post-incident review and testing

Covered in:CISM

Frequently Asked Questions

Explore More Certifications

Browse all certification paths across AWS, Azure, CompTIA, and more.

Browse All Certifications