CISM - Certified Information Security Manager¶
Exam Overview¶
The Certified Information Security Manager (CISM) is ISACA's flagship certification for information security management. Where CISSP demonstrates broad technical security knowledge and CISA validates audit and assurance skills, CISM is explicitly the manager's credential. It validates the ability to design, manage, and oversee an enterprise information security program that aligns with business objectives.
CISM is in heavy demand for security leadership roles: CISO, security director, security program manager, risk manager, and security consultant who interface with business stakeholders. It is referenced by US Department of Defense directive 8140 (formerly 8570), recognized by ANSI under ISO/IEC 17024, and is among the highest-paid IT certifications globally.
Exam Details: - Exam Code: CISM - Format: Linear, fixed-form - Duration: 4 hours (240 minutes) - Number of Questions: 150 multiple-choice - Passing Score: 450 out of 800 (scaled) - Cost: $575 USD (ISACA member), $760 USD (non-member) - Languages: English, Chinese (Simplified), Japanese, Korean, Spanish - Delivery: PSI testing centers and online proctored - Validity: 3 years (recertification via 120 CPE credits) - Prerequisites for certification: 5 years of work experience in information security, with 3 years specifically in information security management across at least 3 of the 4 CISM domains. Experience must be earned within the 10 years preceding the application or within 5 years after passing the exam.
You may sit for the exam without the experience and submit the experience verification within 5 years.
Four CISM Domains (2022 Refresh, current)¶
Domain 1: Information Security Governance (17%)¶
- Organizational culture and security strategy
- Legal, regulatory, and contractual requirements
- Information security strategy development
- Information governance frameworks and standards (COBIT, ISO 27001/27014, NIST CSF)
- Strategic planning and roadmap
- Information security roles and responsibilities (RACI, three lines of defense)
- Senior leadership commitment and accountability
- Business case for security investment
- Steering committees and reporting lines
Domain 2: Information Security Risk Management (20%)¶
- Emerging risk and threat landscape
- Vulnerability and control deficiency analysis
- Risk assessment, evaluation, and analysis (qualitative and quantitative)
- Risk treatment and response options (mitigate, transfer, avoid, accept)
- Risk monitoring and reporting
- Risk register management
- Inherent risk vs residual risk
- Risk ownership and risk appetite
- Risk frameworks (NIST 800-30, NIST 800-39, ISO 27005, FAIR, OCTAVE)
- Quantitative formulas (SLE, ALE, ARO, EF, ROSI)
Domain 3: Information Security Program (33%)¶
- Information security program resources (people, process, technology)
- Information asset identification, classification, and ownership
- Industry standards and frameworks for information security
- Information security policies, procedures, and guidelines
- Information security program metrics and reporting
- Information security control design, selection, and implementation
- Security awareness, training, and communications
- Integration with business processes (HR, procurement, change, project management)
- External services management (vendor and third-party security)
- Information security program communications and reporting (KPIs, KRIs, KGIs)
Domain 4: Incident Management (30%)¶
- Incident response plan development
- Business impact analysis (BIA) and business continuity (BCP)
- Disaster recovery planning (DRP)
- Incident classification, categorization, and prioritization
- Incident management training, testing, and evaluation
- Incident management tools and technologies
- Incident investigation and forensics
- Incident containment methods
- Incident response communications (internal, regulatory, customer, media)
- Incident eradication and recovery
- Post-incident review and lessons learned
- Integration with BCP/DR (NIST 800-34, ISO 22301)
- Incident response frameworks (NIST 800-61, ISO 27035)
Study Materials¶
Notes¶
- 01 - Information Security Governance
- 02 - Information Security Risk Management
- 03 - Information Security Program
- 04 - Incident Management
Study Resources¶
- Fact Sheet - Quick reference
- Practice Plan - 12 to 16 week study schedule
- Scenarios - Realistic CISM-style management scenarios
- Strategy - Manager-mindset exam tactics
Audience and Career Profile¶
CISM is targeted at security professionals transitioning into or already in management roles. Common roles:
- Chief Information Security Officer (CISO)
- Information Security Manager / Director
- Information Security Program Manager
- IT Risk Manager
- Security Compliance Manager
- Security Consultant (advising executive stakeholders)
- IT Director with security responsibility
- Information Assurance Manager (DoD)
Unlike CISSP, which is heavy with technical depth, CISM expects you to think and answer like the executive who owns the program: balancing risk against business value, justifying spend to the board, and translating technical realities into strategic decisions.
Companion Certifications¶
| Cert | How it relates to CISM |
|---|---|
| CISA (ISACA) | Sister certification focused on audit and assurance. CISA tests the auditor's perspective; CISM tests the manager's. |
| CISSP (ISC2) | Significant content overlap, but CISSP is broader and more technical. Many CISOs hold both. |
| CRISC (ISACA) | Risk-focused sibling. CRISC zooms in on risk; CISM covers risk plus governance, program, and incident. |
| CGEIT (ISACA) | IT governance focused, broader than CISM but less security-specific. |
| AWS Certified Security - Specialty | Cloud-specific technical depth, complements CISM management view. |
| Azure SC-100 (Cybersecurity Architect Expert) | Microsoft equivalent of strategic security architecture; pairs well with CISM for cloud-heavy enterprises. |
| GIAC GSLC | Hands-on security leadership certification, more technical than CISM. |
| ISO 27001 Lead Implementer / Auditor | Practical ISMS deployment; CISM gives the strategy, ISO 27001 gives the implementation. |
Official Resources¶
- CISM Certification Page: https://www.isaca.org/credentialing/cism
- CISM Exam Content Outline: https://www.isaca.org/credentialing/cism/cism-exam-content-outline
- CISM Review Manual (ISACA bookstore) - the gold-standard reference
- CISM Review Questions, Answers, and Explanations Manual (ISACA)
- ISACA online review course - instructor-led or self-paced
- CPE policy and recertification: https://www.isaca.org/credentialing/how-to-maintain-your-certification
Recommended Training¶
Books¶
- CISM Review Manual, 16th Edition (ISACA) - the official text
- CISM Review Questions, Answers and Explanations, 10th Edition (ISACA) - official Q-bank
- CISM Certified Information Security Manager All-in-One Exam Guide by Peter Gregory (McGraw Hill)
- CISM Certified Information Security Manager Study Guide by Mike Chapple (Sybex)
Video Courses¶
- Hemang Doshi CISM (Udemy) - high pass rate among study groups
- Pluralsight CISM path - structured by domain
- ITProTV / ACI Learning CISM - short, focused modules
- ISACA Official Online Review Course
Practice Tests¶
- ISACA QAE database (official)
- Hemang Doshi practice question bank (Udemy)
- Pocket Prep CISM
- Boson CISM (less mature than their CISSP, but useful)
Communities¶
- r/cism on Reddit
- ISACA Engage online community
- LinkedIn ISACA chapter groups
After You Pass¶
- Submit CISM application within 5 years of passing
- Document 5 years of qualifying experience (3 in security management) verified by an employer or supervisor
- Pay the application fee
- Begin earning 120 CPE credits over 3 years (minimum 20 CPE per year)
- Pay annual maintenance fee (currently around $45 ISACA member, $85 non-member)
- Adhere to ISACA Code of Professional Ethics
Mindset Tip¶
CISM is a manager's exam. When you see two answers that both look correct, pick the one that:
- Aligns security to business objectives (not the most technically thorough answer)
- Manages risk based on appetite (not eliminates risk)
- Has executive sponsorship (not just technical authority)
- Is strategic and repeatable (not one-off and tactical)
- Communicates value to stakeholders (not just protects assets)
If a CISSP-trained brain wants to pick "patch the system", a CISM-trained brain picks "review the patch management policy with the steering committee". This perspective is the single biggest determinant of exam success for technically strong candidates.