Certified Information Security Manager Exam Guide
At a glance
- Questions
- 150
- Time limit
- 4h
- Passing score
- 450 on a scale of 200 to 800
- Exam fee
- $760
- Governing body
- ISACA
Quick answers
How much does the CISM cost?
The CISM exam fee is $760 (non-members; $575 ISACA members).
What is the passing score for the CISM?
The passing score for the CISM is 450 on a scale of 200 to 800.
How many questions is the CISM?
The CISM has 150 questions with a time limit of 4 hours.
The Certified Information Security Manager (CISM) is a globally recognized credential for IT security leaders and risk managers. ISACA designed CISM for professionals who oversee security programs, lead incident response, and align security strategy with business objectives. This certification validates your ability to govern information security across enterprise environments.
Overview
CISM exam content spans 4 job practice domains: Information Security Governance (17%), Information Security Risk Management (20%), Information Security Program (33%), and Incident Management (30%). The domains reflect real-world leadership responsibilities—from establishing governance frameworks and managing risk to building security programs and handling security incidents.
Cost and registration
The CISM exam registration fee is US$575.00 for ISACA members and US$760.00 for non-members. This covers your exam registration and eligibility to schedule. Membership in ISACA offers a fee discount, making it cost-effective for committed candidates planning a multi-year certification path.
Exam format
CISM is a 150-question, 4-hour (240-minute) exam. Each question presents a stem and 4 answer options with one best answer. You'll receive a scaled score on ISACA's 200–800 scale; a score of 450 or higher is required to pass. Testing is available in-person at test centers or online via remote proctoring through PSI.
Verified facts about the CISM
19 statements, each bound to the official document it was taken from. The source link beside every line opens that document.
Requirements and rules
- Cert application window years
- Candidates have 5 years from passing the exam to apply for CISM certification
- ISACA
- Delivery modes
- The CISM exam is delivered either at an In-Person Test Center or as an Online Remote Proctored exam via PSI
- ISACA
- Registration before scheduling
- Candidates must first register and pay before being notified by email that they are eligible to schedule the CISM exam on the PSI platform
- PSI
- Reschedule window hours
- All rescheduling and cancelling of a CISM testing appointment must be done a minimum of 48 hours prior to the scheduled appointment
- ISACA
Fees
Numbers
What is tested
- Domain1 governance weight
- Domain 1, Information Security Governance, accounts for 17% of the exam%
- ISACA
- Domain2 risk weight
- Domain 2, Information Security Risk Management, accounts for 20% of the exam%
- ISACA
- Domain3 program weight
- Domain 3, Information Security Program, is the largest domain at 33% of the exam%
- ISACA
- Domains list
- The four CISM domains are Information Security Governance, Information Security Risk Management, Information Security Program, and Incident Management
- ISACA
How hard is the CISM?
How Hard Is the CISM Certification Exam?
The Certified Information Security Manager (CISM) exam stands as one of the information security field's most respected and rigorous certifications. Administered by ISACA, the CISM tests not just technical knowledge but strategic security management capabilities across a comprehensive body of job practice domains. Understanding the exam's difficulty requires looking at both its structure and what preparation truly demands.
Exam Structure and Format
The CISM exam is delivered either at an In-Person Test Center or as an Online Remote Proctored exam via PSI, giving candidates flexibility in how they sit for the assessment. The exam itself contains 150 multiple-choice questions, all structured with a stem and 4 answer options with one best answer. Candidates have 240 minutes (4 hours) to complete the exam.
The exam operates on a scaled scoring system rather than raw or percentage scores. Candidates must receive a scaled score of 450 or higher to pass, on ISACA's common scale from 200 to 800. This scaled approach means that the difficulty calibration of questions in any given exam administration is normalized, preventing variance in passing rates across different test dates.
| Exam Element | Detail |
|---|---|
| Total Questions | 150 |
| Answer Options per Question | 4 |
| Total Duration | 240 minutes (4 hours) |
| Passing Score | 450 (on 200–800 scale) |
| Exam Fee (ISACA Members) | $575.00 |
| Exam Fee (Non-Members) | $760.00 |
| Delivery Options | In-Person Test Center or Online Remote Proctored |
Domain Coverage and Weighting
The CISM exam covers 4 job practice domains, each weighted to reflect its importance in security management practice. The four domains are Information Security Governance, Information Security Risk Management, Information Security Program, and Incident Management.
Domain 1, Information Security Governance, accounts for 17% of the exam. This domain covers how organizations establish strategic direction, oversight structures, and policies. Domain 2, Information Security Risk Management, accounts for 20% of the exam, focusing on identifying, analyzing, and mitigating security risks. Domain 3, Information Security Program, is the largest domain at 33% of the exam, reflecting the breadth of activities required to build and sustain an effective security program. Finally, Domain 4, Incident Management, accounts for 30% of the exam, covering detection, response, recovery, and lessons learned from security incidents.
The dominance of Domain 3 signals that the exam prioritizes breadth of program management over depth in any single area. This means preparation requires a holistic understanding of how security functions integrate and operate together, rather than mastery of isolated technical concepts.
Difficulty Assessment
The CISM is considered one of the harder information security certifications to pass, though not for technical depth alone. The exam's difficulty stems from several factors: the breadth of domains that must be understood, the management perspective required (not just technical implementation), and the scenario-based nature of many questions. Unlike some certifications that can be passed through memorization, CISM questions often present realistic security situations and ask candidates to identify the best action or decision from imperfect options.
The scaled scoring requirement of 450 out of 800 seems approachable until you factor in the breadth of material. Few candidates can walk into the exam without deliberate preparation and pass comfortably.
The exam draws from ISACA's official CISM review manual and real-world security management practice. Questions test not just knowledge recall but judgment: whether you understand when to prioritize risk management over compliance, how to communicate security business case, and how incident response overlaps with governance. These judgment calls are harder to study for than facts.
Preparation Approach
Effective CISM preparation requires a structural approach across multiple dimensions. Begin by establishing foundational knowledge across all four domains through official ISACA materials, learning governance structures, risk frameworks, program controls, and incident response processes. The study sequence should prioritize domains by exam weight: start with Domain 3 (Information Security Program) to establish the conceptual backbone, then move to Domains 2 and 4 (Risk Management and Incident Management) concurrently. Complete your foundation with Domain 1 (Governance), which often tests conceptual thinking and executive alignment.
Hands-on experience matters significantly. Candidates with direct security management experience have an advantage because they recognize patterns from real projects. If your background is primarily technical, seek opportunities to observe risk assessments, audit preparations, or incident response activities to build intuition.
Practice questions are essential for identifying weak areas and understanding how ISACA frames questions. Work through question banks systematically, reviewing why correct answers are superior. Review weak domains repeatedly until your performance stabilizes. Readiness signals include consistently strong performance on full-length practice exams and demonstrating ability to reason through unfamiliar scenarios by applying domain principles rather than relying on recognition.
Registration and Scheduling
Candidates must first register and pay before being notified by email that they are eligible to schedule the CISM exam on the PSI platform. This means you cannot schedule until payment is confirmed. Once notified, you can schedule at an available test center or online proctoring slot. All rescheduling and cancelling of a CISM testing appointment must be done a minimum of 48 hours prior to the scheduled appointment, so plan accordingly if circumstances change.
An important detail: candidates have 5 years from passing the exam to apply for CISM certification. Passing the exam and earning the credential are two separate steps. You must also meet experience and education requirements, which are verified during certification application.
Is It Worth the Effort?
The CISM's difficulty is intentional. ISACA maintains rigorous standards because organizations hiring CISM-certified professionals expect them to drive security strategy and manage complex programs, not just execute technical tasks. The exam's breadth and judgment-based questions reflect that bar. The exam demands sustained engagement with security management concepts, strategic thinking across multiple domains, and demonstrated ability to learn from official materials and practice questions.
CISM is most valuable for security practitioners stepping into or already in management roles. If you lead security teams, make risk decisions, or report to the CISO, this credential signals to employers that you've validated your strategic security knowledge. Study materials are available through ISACA, including official guides and practice exam banks, and many candidates supplement with formal courses or bootcamps.
Difficulty is relative to preparation. Many candidates who fail did so not because the exam was impossibly hard, but because they underestimated breadth and relied on cramming. Those who passed typically invested consistent effort across all four domains, worked practice questions to mastery, and approached the exam as testing judgment, not just recall.
Ways to prepare for the CISM
Each of these is a side-by-side on what the provider does better than we do, what it charges today, and where the free path here is enough.
Frequently asked questions
How much does the CISM exam cost?
The CISM exam registration fee is US$575.00 for ISACA members and US$760.00 for non-members. Because the non-member price is US$185 higher than the member rate, weigh the cost of an ISACA membership against that difference — for many candidates, joining before registering effectively offsets much of the gap on the exam fee alone.
How many questions are on the CISM exam and how long is it?
The CISM exam consists of 150 multiple-choice questions and you have 240 minutes (4 hours) to complete it. Every question has a stem and four answer options, each designed with one best answer. That works out to an average of roughly 1.6 minutes per question, so practice pacing yourself and leave time to review flagged items.
What is a passing score on the CISM exam and how is it scored?
CISM scores are reported as scaled scores rather than raw or percentage scores. ISACA uses a common scale from 200 to 800, where 800 represents a perfect score, and you must receive a scaled score of 450 or higher to pass. Because scaling accounts for differences in question difficulty across exam forms, the 450 threshold does not map to a fixed percentage of correct answers — focus on mastering the content rather than targeting a specific raw percentage.
What domains does the CISM exam cover and how are they weighted?
The CISM exam covers four job practice domains that together comprise 100% of the 150-question exam: Information Security Governance (17%), Information Security Risk Management (20%), Information Security Program (33%), and Incident Management (30%). Since Domain 3, Information Security Program, is the largest at 33% and Domain 4, Incident Management, follows at 30%, these two domains alone account for well over half the exam — prioritize them when allocating your study time.
How hard is the CISM exam?
The CISM exam is demanding because it is a four-hour, management-level test: ISACA sets the exam length at 240 minutes and includes 150 multiple-choice questions, which leaves under two minutes per item. According to ISACA, every question has a stem and four answer options designed with one best answer, so the difficulty comes less from recall and more from choosing the best managerial response among several defensible ones. ISACA spreads the exam across four job practice domains, meaning you cannot pass by mastering only the technical material.
What is the passing score for CISM, and is there a published pass rate?
You need a scaled score of 450 or higher to pass, on ISACA's common scale that runs from 200 to 800. ISACA reports results as scaled scores rather than raw or percentage scores, so 450 does not correspond to answering 450 out of 800 questions or to any fixed percentage correct. ISACA does not publish an official CISM pass rate in the exam materials cited here, so any pass-rate figure you see quoted elsewhere should be treated as unverified.
How should I study for CISM, and where should I focus?
Weight your study time to the domain weights ISACA publishes, because they are far from even. According to ISACA, Domain 3, Information Security Program, is the largest at 33% of the exam, and Domain 4, Incident Management, accounts for 30%, so those two together make up nearly two-thirds of the questions. Domain 2, Information Security Risk Management, accounts for 20% and Domain 1, Information Security Governance, for 17% — still worth solid coverage, since governance concepts underpin the answer choices in every other domain.
Where do I take the CISM exam, and can I reschedule?
You can take CISM either at an in-person test center or as an online remote proctored exam, both delivered through PSI, which is ISACA's exam delivery vendor. Rescheduling or cancelling a testing appointment must be done a minimum of 48 hours before the scheduled appointment, so put that deadline in your calendar as soon as you book. Because scheduling only opens after you register and pay, plan the payment step earlier than you think you need to.
How long do I have to get certified after passing the exam?
Candidates have five years from passing the exam to apply for CISM certification, according to ISACA. ISACA also notes that exam eligibility itself is valid for six months from the date of registration, so the clock starts running before you ever sit down to test. In practice that means two separate deadlines to track: one to take the exam after registering, and a much longer one to complete your certification application after passing.
Sources
- 1.CISM Exam Content Outline — ISACA (accessed Jul 18, 2026)
- 2.CISM Certification Overview — ISACA (accessed Jul 18, 2026)
- 3.ISACA Certification Exam Candidate Guide — ISACA (accessed Jul 18, 2026)
- 4.CISA/CRISC/CISM/CGEIT/CDPSE Exam Scheduling Guide — ISACA (accessed Jul 18, 2026)
- 5.ISACA Credentials — ISACA
- 6.ISACA (CISA/CRISC/CISM/CGEIT) Scheduling Guide — PSI (accessed Jul 18, 2026)
Official sources
Primary documents used to verify the exam details shown on this page.
- ISACA Certification Exam Candidate GuideISACAisaca.org
- CISM Exam Content OutlineISACAisaca.org
- CISM Certification OverviewISACAisaca.org
- ISACA (CISA/CRISC/CISM/CGEIT) Scheduling GuidePSIproctor2.psionline.com
- CISA/CRISC/CISM/CGEIT/CDPSE Exam Scheduling GuideISACAisaca.org
Last verified against the official exam content outline: