CISM Practice Plan - 12 to 16 Week Schedule¶
CISM is a manager-focused exam covering 4 domains. Most successful candidates spend 8 to 16 weeks preparing. This plan assumes 8 to 12 hours per week of focused study and is designed for a candidate who already has practical security experience and is shifting toward management thinking.
If you are already a security manager or CISO, you can compress to 8 to 10 weeks. If you are still mostly hands-on technical, plan 14 to 18 weeks because the mindset shift takes longer than the content.
Experience Requirement Reminder¶
CISM requires 5 years of information security work experience, with at least 3 years specifically in information security management across at least 3 of the 4 CISM domains. Experience must be earned within the 10 years preceding application, or within 5 years after passing the exam. Experience substitutions (CISA, CISSP, MS in InfoSec, ISO 27001 LA/LI) can offset up to 2 years.
You may sit for the exam without the experience and submit your application later, within 5 years of passing. Many candidates do this to lock in the exam result while accumulating qualifying experience.
Materials Required¶
Before starting: - CISM Review Manual, 16th Edition (ISACA) - primary text - CISM Review Questions, Answers and Explanations Manual (ISACA) - official Q-bank - ISACA QAE database (online practice questions) - simulates the exam - Hemang Doshi CISM (Udemy) OR Pluralsight CISM path - video course - CISM All-in-One Exam Guide by Peter Gregory (McGraw Hill) - alternative narrative
Optional additions: - Mike Chapple's Sybex CISM Study Guide - second narrative pass - Thor Pedersen CISM (Udemy) - exam tips and memorization aids - Anki flashcards for frameworks, formulas, IR phases
Mindset Shift (Start Here, Continue Throughout)¶
CISM is a manager exam. Before opening any technical content, internalize this:
- The CISM-correct first action to most situations is engage stakeholders, scope, or assess - not deploy or fix.
- Risk is managed against appetite, not eliminated.
- Strategy beats tactics; alignment to business beats best-of-breed technology.
- Process and policy beat tools.
- Senior management owns risk acceptance.
- Information security exists to enable the business, not to police it.
If you have a CISSP or hands-on background, your hardest job is to stop choosing the technically perfect answer and start choosing the strategically correct answer.
Week-by-Week Plan (12-Week Compressed)¶
Week 1: Orientation and Domain 1 Part 1 (Governance Foundations)¶
Goals: Understand exam format, ISACA ethics, governance fundamentals.
Topics: - Exam format (150 questions, 4 hours, scaled scoring) - ISACA Code of Professional Ethics (memorize the 7 principles) - Information security governance vs management (Cadbury, COBIT) - Three lines of defense - COBIT 2019, NIST CSF, ISO 27001 / 27014 - Information security strategy as a function of business strategy - Policies, standards, procedures, guidelines, baselines
Activities: - Read CISM Review Manual Domain 1 (first half) - Watch Domain 1 video content (first half) - 30 to 50 official QAE questions on Domain 1 - Build flashcards for frameworks and ethics
Deliverable: Written one-page narrative explaining how you would brief a new CEO on the security program.
Week 2: Domain 1 Part 2 (Strategy and Business Case)¶
Topics: - Strategy development: current state, target state, gap analysis, roadmap - Business case for security investment (risk-based, business-aligned) - Roles and responsibilities (CISO, ISO, ISSM, ISSO, data owner, custodian, RACI) - Steering committees and governance structures - Reporting lines (CIO vs CEO vs board) - Legal, regulatory, and contractual requirements as governance inputs - Risk appetite and tolerance setting
Activities: - Read remainder of Domain 1 chapter - Build a sample governance structure diagram - Practice 50 QAE questions on governance
Week 3: Domain 2 Part 1 (Risk Identification and Assessment)¶
Topics: - Risk concepts: threat, vulnerability, asset, control, exposure, risk - Inherent vs residual risk, risk appetite vs tolerance vs capacity - Asset identification, valuation, classification - Threat and vulnerability identification (sources, internal/external/environmental) - Risk assessment methodologies (NIST 800-30, ISO 27005, OCTAVE, FAIR) - Qualitative analysis (likelihood x impact matrix) - Quantitative analysis (SLE, ALE, ARO, EF, ROSI)
Activities: - Solve 10 quantitative risk problems by hand (asset value, EF, SLE, ARO, ALE) - 50 to 75 QAE questions on Domain 2 risk basics - Build a sample risk register entry end-to-end
Week 4: Domain 2 Part 2 (Risk Treatment and Monitoring)¶
Topics: - Risk treatment options (mitigate, transfer, avoid, accept) - Risk acceptance and ownership (who signs off) - Control selection: preventive, detective, corrective, deterrent, recovery, compensating - Risk register management - Risk monitoring, KRIs, threshold triggers - Continuous risk assessment in changing environment - Emerging risks (cloud, supply chain, AI, OT, geopolitical)
Activities: - Read remainder of Domain 2 - 75 QAE questions on risk treatment - Map a sample risk through the full lifecycle (identify, assess, treat, monitor, report)
Week 5: Mid-Course Diagnostic + Domain 3 Part 1¶
Goals: Take a 100-question diagnostic spanning Domains 1 and 2. Address weak areas.
Topics: - Information security program objectives and scope - Program management: people, process, technology - Information security architecture - Control frameworks: ISO 27002, NIST 800-53, CIS Controls - Policy development lifecycle (draft, approve, communicate, enforce, review)
Activities: - 100-question diagnostic from QAE (across all domains) - Build a remediation list of low-scoring sub-areas - Begin Domain 3 reading
Week 6: Domain 3 Part 2 (Resources, Awareness, Operations Integration)¶
Topics: - Resource management (staffing, budget, third-party) - Information asset identification, classification, ownership, lifecycle - Awareness, training, and education (SETA) - Phishing simulation programs - Communications planning (executive, technical, employee, customer) - Integration with HR, procurement, legal, IT operations - Change management and SDLC integration - Project management touchpoints
Activities: - Read Domain 3 second half - 75 QAE questions - Build a SETA program outline (audience, frequency, content, metrics)
Week 7: Domain 3 Part 3 (Vendor, Metrics, Reporting)¶
Topics: - Third-party / vendor risk management lifecycle - Contractual controls (DPA, BAA, MSA, SLA, right to audit, data return) - Continuous monitoring tools (BitSight, SecurityScorecard, SecurityScorecard, etc.) - Metrics: KGI, KPI, KRI, capability/maturity (CMMI, NIST CSF tiers) - Reporting cadence and audience (board, exec, ops) - Communicating value: dashboards, scorecards, executive summaries - Continuous improvement (PDCA, Six Sigma DMAIC)
Activities: - Build sample executive scorecard with at least 3 KGI, 5 KPI, 5 KRI - 50 QAE questions on metrics and reporting - 50 questions on vendor / third-party
Week 8: Domain 4 Part 1 (Incident Management Foundations)¶
Topics: - IR plan development (policy, procedures, runbooks, contact lists) - IR roles (IR commander, lead, scribe, comms lead, legal, technical responder) - Incident classification, categorization, severity, prioritization - IR phases (NIST 800-61): preparation, detection and analysis, containment/eradication/recovery, post-incident - ISO 27035 phases - IR tooling (SIEM, EDR, SOAR, ticketing, war-room platforms) - Detection sources (alerts, threat intel, user reports, third-party notification)
Activities: - Read Domain 4 first half - 75 QAE questions on Domain 4 fundamentals - Build an incident classification matrix and escalation tree
Week 9: Domain 4 Part 2 (Containment, Recovery, Communication)¶
Topics: - Containment strategies (short-term, long-term, evidence-preserving) - Eradication and recovery - Forensic procedures, chain of custody, evidence handling - Crisis communication (internal, customer, regulator, media, law enforcement) - Breach notification timelines (GDPR 72h, HIPAA 60d, state laws, contractual) - Post-incident review and lessons learned - Incident management training, testing, evaluation - Tabletop and red/purple team exercises
Activities: - Walk through a ransomware scenario end-to-end as IR commander - 75 QAE questions on Domain 4 response - Draft a sample external breach notification message (no sending)
Week 10: Domain 4 Part 3 (BCP/DR Integration)¶
Topics: - BIA: identify critical functions, dependencies, impact tolerance - Recovery objectives: RTO, RPO, MTD, WRT - Recovery sites and strategies (cold/warm/hot/mirrored/cloud) - Backup strategies (full, incremental, differential, snapshots, replication, immutable) - BCP/DRP testing: read-through, walk-through, tabletop, simulation, parallel, full interruption - Pandemic and large-scale disruption planning - Insurance and continuity arrangements
Activities: - Build a sample BIA for one business function - Build a comparison chart of recovery sites and test types - 75 QAE questions
Week 11: First Full-Length Practice Exam + Weak Domain Focus¶
Goals: Take a full 150-question simulated exam. Identify weak domains.
Activities: - Take ISACA QAE 150-question full-length exam under exam conditions (4 hours, no reference) - Review every wrong answer in depth (write the explanation in your own words) - Re-read weak chapters - Build new flashcards for missed concepts - Begin daily 30-minute flashcard review
Week 12: Second Full-Length Practice Exam + Final Review¶
Goals: Confirm readiness with a second full-length and tighten weak spots.
Days 1-3: - Take a second 150-question full-length from a different vendor (Hemang Doshi or Boson) - Target 75%+ pass rate - Address remaining weak areas
Days 4-5: - Light review only - no new material - Re-watch any video module on your weakest domain - Mind maps and summary sheets - Mental rehearsal of exam-day logistics
Day 6: - REST. No studying after early afternoon. - Light exercise, normal sleep, hydration
Exam Day: - Eat protein-rich breakfast - Arrive 30 minutes early at the test center, or set up online proctoring environment - Photo ID required - 4 hours, breaks built in (the clock pauses at scheduled breaks for online proctored) - Trust your preparation
16-Week Variant (Standard Pace)¶
Insert these between weeks 11 and 12 of the compressed plan:
Week 12 of 16: Cross-Domain Synthesis¶
- Walk through 5 sample CISM-style scenarios that span multiple domains
- Build a personal "CISM mindset checklist" you can mentally apply
Week 13 of 16: Memorization Sprint¶
- Frameworks (NIST CSF, ISO 27001, COBIT, NIST RMF)
- IR phases (NIST 800-61 and ISO 27035)
- Risk formulas (SLE, ALE, ROSI)
- Three lines of defense
- KGI/KPI/KRI
- Privacy regulation timelines
Week 14 of 16: Third Full-Length Practice Exam¶
- Different vendor (Pocket Prep or Pluralsight skill assessment)
- Identify final weak spots
- Daily flashcard sessions
Week 15 of 16: Targeted Domain Deep-Dive¶
- Spend 5 days on weakest domain
- Re-read CISM Review Manual chapter
- Re-watch video, build new notes
- 100 questions on that domain
Daily Habits Throughout¶
- 30 to 60 minutes of practice questions every day except rest day
- Anki flashcards - 15 minutes/day; new cards from current chapter, review old cards
- Concept journal - one paragraph per day on a confusing topic, written in your own words
- Study group - weekly call with 1 to 3 other CISM candidates if possible (LinkedIn ISACA chapter is a good source)
Practice Exam Score Targets¶
- Week 5 (mid-diagnostic): 50%+
- Week 11 (first full-length): 65 to 70%
- Week 12 (second full-length): 75%+
- Exam day: ready when consistently 75%+ on QAE and 80%+ on Hemang Doshi or Boson
The CISM scaled passing score is 450 / 800. On the official QAE database, 75% raw score is a reasonable correlation to passing.
Mindset Daily Reminders¶
- CISM rewards manager-level thinking, not technician-level
- Best answer, not only correct answer
- Business alignment first, controls second
- Risk-based decisions, not zero-risk decisions
- Strategy and process beat technology
After You Pass¶
- Submit CISM application within 5 years
- Document 5 years experience (3 in security management) verified by a supervisor or employer
- Pay application fee
- Update LinkedIn (use "CISM" only after application is approved; until then, "passed CISM exam")
- Begin tracking CPEs immediately - 120 over 3 years (20 min per year)
- Consider companion: CISA, CRISC, CGEIT, CDPSE