ISACA Certified Information Security Manager (CISM) Study Guide [61 Minute Read]
A First-Principles Approach to Information Security Management
CISM is not a technical exam — it tests whether you can think like the person accountable for an organization's information risk, not the person configuring its firewalls. This guide builds every concept from the ground up around that "manager, not technician" mental model, so you walk into the exam room reasoning the way ISACA wants you to reason, not just recalling terms.
Official Exam Objectives: CISM Exam Content Outline
CISM is almost entirely scenario-based: most stems describe a situation and ask for the MOST appropriate, BEST, or FIRST action — several answer choices are technically defensible, and the exam rewards the one a security manager would pick given limited time, incomplete information, and competing business priorities. Expect very few pure recall questions.
Exam details: 150 multiple-choice questions, 4 hours, scaled score of 450 out of 800 to pass (not a flat percentage — item difficulty is weighted). CISM certification also requires 5 years of cumulative information security management work experience (some substitutions allowed), though you can sit the exam itself before that experience is verified.
Exam Domain Weights
Notice that the two "build and run the program" domains — Program (33%) and Incident Management (30%) — together make up nearly two-thirds of the exam. Governance and Risk Management set direction; Program and Incident Management are where that direction gets executed and tested under pressure. Study time should track this weighting, not intuition about which domain "feels" most important.
Start Free. Upgrade When You're Ready.
Stay on your structured path while adding targeted practice with the full set of exam-like questions, expanded flashcards to reinforce concepts, and readiness tracking to identify and address weaknesses when needed.
Frequently Asked Questions
Content last updated