Certified Information Security Manager Exam Guide
At a glance
- Questions
- 150
- Time limit
- 4h
- Passing score
- 450 on a scale of 200 to 800
- Exam fee
- $760
- Governing body
- ISACA
The Certified Information Security Manager (CISM) is a globally recognized credential for IT security leaders and risk managers. ISACA designed CISM for professionals who oversee security programs, lead incident response, and align security strategy with business objectives. This certification validates your ability to govern information security across enterprise environments.
CISM exam content spans 4 job practice domains: Information Security Governance (17%), Information Security Risk Management (20%), Information Security Program (33%), and Incident Management (30%). The domains reflect real-world leadership responsibilities—from establishing governance frameworks and managing risk to building security programs and handling security incidents.
The CISM exam registration fee is US$575.00 for ISACA members and US$760.00 for non-members. This covers your exam registration and eligibility to schedule. Membership in ISACA offers a fee discount, making it cost-effective for committed candidates planning a multi-year certification path.
CISM is a 150-question, 4-hour (240-minute) exam. Each question presents a stem and 4 answer options with one best answer. You'll receive a scaled score on ISACA's 200–800 scale; a score of 450 or higher is required to pass. Testing is available in-person at test centers or online via remote proctoring through PSI.
Frequently asked questions
How much does the CISM exam cost?
The CISM exam registration fee is US$575.00 for ISACA members and US$760.00 for non-members. Because the non-member price is US$185 higher than the member rate, weigh the cost of an ISACA membership against that difference — for many candidates, joining before registering effectively offsets much of the gap on the exam fee alone.
How many questions are on the CISM exam and how long is it?
The CISM exam consists of 150 multiple-choice questions and you have 240 minutes (4 hours) to complete it. Every question has a stem and four answer options, each designed with one best answer. That works out to an average of roughly 1.6 minutes per question, so practice pacing yourself and leave time to review flagged items.
What is a passing score on the CISM exam and how is it scored?
CISM scores are reported as scaled scores rather than raw or percentage scores. ISACA uses a common scale from 200 to 800, where 800 represents a perfect score, and you must receive a scaled score of 450 or higher to pass. Because scaling accounts for differences in question difficulty across exam forms, the 450 threshold does not map to a fixed percentage of correct answers — focus on mastering the content rather than targeting a specific raw percentage.
What domains does the CISM exam cover and how are they weighted?
The CISM exam covers four job practice domains that together comprise 100% of the 150-question exam: Information Security Governance (17%), Information Security Risk Management (20%), Information Security Program (33%), and Incident Management (30%). Since Domain 3, Information Security Program, is the largest at 33% and Domain 4, Incident Management, follows at 30%, these two domains alone account for well over half the exam — prioritize them when allocating your study time.