Certified Information Security Manager Study Guide
- Questions
- 150
- Time limit
- 4h
- Passing score
- 450 on a scale of 200 to 800
- Exam fee
- $760
- Governing body
- ISACA
Certified Information Security Manager (CISM) is a globally recognized credential from ISACA built for professionals who manage, design, and oversee an organization's information security program rather than performing hands-on technical security work. Where many security certifications focus on tools and technical controls, CISM is deliberately management-oriented: it validates your ability to align security strategy with business objectives, manage risk at the enterprise level, build and run a security program, and lead incident response efforts.
CISM is best suited for information security managers, IT directors, security consultants, risk officers, and IT auditors who already have hands-on experience and are moving into governance and leadership roles. It is also a common target for technical security specialists (like those coming from penetration testing or SOC analyst backgrounds) who want to demonstrate they can operate at the program and policy level, not just the technical level.
Why It Matters
- It signals to employers that you can translate security work into business risk language executives understand.
- It is frequently listed as a preferred or required credential for CISO, security manager, and senior GRC roles.
- It complements more technical certifications, rounding out a resume with governance and program-management credibility.
- ISACA's ongoing continuing education requirements mean the credential reflects up-to-date knowledge, not a one-time test.
Because the exam emphasizes judgment and prioritization over rote memorization, candidates typically benefit most when they already have real-world exposure to security governance, risk management, or incident handling before attempting it.
Understanding the mechanics of the CISM exam helps you plan your study timeline and testing-day logistics well in advance.
Format and Timing
- The exam contains 150 questions, each a stem with four answer options and a single best answer.
- You are given 240 minutes (4 hours) to complete the exam.
- All questions are multiple-choice, drawn from ISACA's official job practice areas.
Scoring
CISM results are not reported as a raw count or percentage correct. Instead, ISACA uses a scaled scoring model ranging from 200 to 800, and candidates must reach a scaled score of 450 or higher to pass. This scaling accounts for slight difficulty variations between exam versions, so a scaled score of 450 always represents the same competency bar regardless of which specific question set you received.
Cost
Exam registration costs $575 for ISACA members and $760 for non-members. Because ISACA membership dues are often less than the fee difference, many candidates join before registering.
Delivery and Scheduling
The exam is delivered through PSI, ISACA's testing vendor, either at an in-person test center or as an online remote-proctored exam. You must register and pay first; ISACA then emails you eligibility confirmation before you can schedule your appointment on the PSI platform. If your plans change, rescheduling or cancelling requires at least 48 hours' notice before your appointment. Once you pass, you have 5 years to formally apply for certification, which also requires verifying the relevant work experience.
The CISM exam is organized into four job practice domains, each weighted differently based on its relative importance to the security manager role. Knowing the weightings helps you allocate study time proportionally.
Domain 1: Information Security Governance (17%)
This domain covers establishing and maintaining a governance framework that ensures security strategy aligns with organizational goals. Expect topics like security strategy development, policy and standards creation, organizational roles and responsibilities, and business case development for security initiatives.
Domain 2: Information Security Risk Management (20%)
This domain focuses on identifying, analyzing, and managing information security risk to keep it within acceptable levels defined by the organization. Key concepts include risk assessment methodologies, risk treatment options, and integrating risk management into broader enterprise risk processes.
Domain 3: Information Security Program (33%)
The largest domain by weight, this covers the design, development, and management of a security program that implements the governance strategy. Topics include security architecture, resource management, program metrics, third-party and vendor security, and awareness training.
Domain 4: Incident Management (30%)
This domain addresses planning, establishing, and managing the capability to detect, respond to, and recover from security incidents. It covers incident response planning, business continuity and disaster recovery integration, forensics considerations, and post-incident review.
Because Domains 3 and 4 together make up nearly two-thirds of the exam, candidates should weight their study time toward program management and incident response without neglecting the governance and risk foundations that tie the whole framework together.
Most working professionals need 8 to 12 weeks of consistent study to prepare for CISM, depending on how much governance and risk experience they already have. Here is a topic-by-topic approach you can compress or extend based on your starting point.
Weeks 1-2: Foundations and Domain 1
Start with an overview of the full job practice framework so you understand how the domains interrelate, then dig into Information Security Governance. Focus on strategy development, policy hierarchies, and how governance ties to overall business objectives.
Weeks 3-4: Domain 2
Move into Risk Management. Practice working through risk assessment scenarios, risk treatment decisions, and how risk appetite and tolerance are set at the organizational level. This domain rewards scenario-based reasoning over memorization.
Weeks 5-7: Domain 3
Since this is the heaviest-weighted domain, give it the most time. Cover security program design, resource and budget management, third-party risk, security architecture concepts, and metrics for measuring program effectiveness.
Weeks 8-9: Domain 4
Study incident management end-to-end: detection, response planning, business continuity and disaster recovery integration, and post-incident analysis. Use tabletop-style scenario questions to practice prioritizing actions during an incident.
Weeks 10-12: Integration and Practice
- Take full-length practice exams under timed conditions to build stamina for the 4-hour session.
- Review missed questions by domain to identify weak spots.
- Revisit glossary terms and flashcards for concepts you consistently mix up.
- In the final week, focus on light review rather than cramming new material.
Throughout your plan, prioritize practicing best-answer style questions, since CISM often presents several technically correct options where only one is best from a management perspective.
Before Exam Day
- Confirm your appointment details early, since rescheduling requires at least 48 hours' notice before your slot.
- Decide in advance whether you prefer an in-person test center or an online remote-proctored session, and prepare accordingly (ID requirements differ, and remote proctoring requires a clear workspace and stable internet).
- Get full rest the night before; a 4-hour exam demands sustained focus.
During the Exam
- Pace yourself against the 240-minute window. With 150 questions, you have roughly 90 seconds per question on average, but some scenario questions will take longer than others.
- Flag uncertain questions and move on rather than getting stuck early, since every question carries equal weight toward your scaled score.
- Read each stem carefully for qualifiers like first, best, or most important, which change the correct answer even when multiple options seem valid.
- Think like a security manager, not a technician. When two answers both sound reasonable, choose the one that best serves business risk and governance objectives.
Common Mistakes to Avoid
- Studying only technical security concepts and neglecting governance and business-alignment thinking, which is where CISM differs most from technical certifications.
- Underestimating Domain 3 and 4 preparation time, since together they represent the majority of the exam.
- Skipping timed practice exams, which leaves candidates unprepared for the pacing and mental fatigue of a 4-hour session.
- Forgetting that scores are scaled, not raw percentages, and then misjudging how close a borderline practice score actually is to passing.
Preparing for CISM does not have to rely on a single textbook. This site offers a set of free study tools designed to reinforce the same domains and terminology the exam covers.
Practice Questions
Domain-tagged practice questions let you drill scenario-based, best-answer style items similar to what you will see on exam day. Working through practice sets by domain helps you identify whether your weak spot is governance, risk, program management, or incident response before you sit the real exam.
Flashcards
Flashcards are useful for quickly reinforcing recurring concepts, such as risk treatment options, governance frameworks, or incident response phases, in short study sessions between longer review blocks.
Glossary
CISM questions often hinge on precise terminology; a scenario may hint at a specific concept without naming it outright. A searchable glossary of information security management terms helps you build the vocabulary fluency needed to recognize what a question is really testing.
Combining these tools with full-length timed practice exams gives you both the breadth (terminology and concepts across all four domains) and the depth (applied scenario reasoning) that CISM demands, without requiring a large upfront investment in paid courseware.
CISM flashcards
30 cards on the highest-yield terms and rules. Grading uses spaced repetition and saves in this browser.
Browse all 30 cards
What are the four CISM job practice domains?
Information Security Governance, Information Security Risk Management, Information Security Program, and Incident Management.
Which CISM domain carries the largest exam weight, and what is it?
Domain 3, Information Security Program, at 33% of the exam — the heaviest of the four domains.
How many questions are on the CISM exam and how long is the testing window?
150 multiple-choice questions administered over 240 minutes (4 hours).
What passing score must a CISM candidate achieve?
A scaled score of 450 or higher on ISACA's common scale of 200 to 800.
Why does ISACA report CISM results as scaled scores instead of raw or percentage scores?
Scaled scoring normalizes results across different exam forms of varying difficulty so that a given scaled score reflects the same level of competency regardless of which version a candidate took.
What is the primary objective of information security governance?
To align information security strategy with business objectives and ensure risks are managed appropriately, so security investments support organizational goals rather than operating in isolation from them.
Define 'risk appetite' as used in information security risk management.
The amount and type of risk an organization is willing to accept in pursuit of its business objectives, set by senior leadership before controls are designed.
What distinguishes inherent risk from residual risk?
Inherent risk is the level of risk that exists before any controls are applied; residual risk is what remains after controls have been implemented and are operating.
What is a Business Impact Analysis (BIA) used for?
To identify critical business processes and determine the impact of their disruption over time, driving recovery time and recovery point objectives for continuity planning.
Differentiate Recovery Time Objective (RTO) from Recovery Point Objective (RPO).
RTO is the maximum acceptable time to restore a process or system after disruption; RPO is the maximum acceptable amount of data loss measured in time, i.e., how far back the last usable backup must be.
What is the purpose of an information security steering committee?
To provide senior-level oversight and cross-functional decision-making that aligns security initiatives with business priorities and secures organizational buy-in.
What does 'due diligence' mean in an information security governance context?
The ongoing process of verifying that reasonable care is being exercised to protect assets, as opposed to 'due care,' which is the actual execution of reasonable protective measures.
What is the role of a RACI chart in security program management?
It clarifies accountability by defining who is Responsible, Accountable, Consulted, and Informed for a given task or decision, reducing ambiguity in security roles.
What is the difference between a policy, a standard, and a procedure?
A policy states management's intent and high-level requirements; a standard specifies mandatory, measurable criteria supporting the policy; a procedure gives step-by-step instructions for carrying out the standard.
What is a key risk indicator (KRI)?
A metric that provides early warning of increasing risk exposure, allowing management to take action before a risk event materializes.
What is the goal of security awareness training within a security program?
To reduce human-factor risk by ensuring personnel understand their security responsibilities and can recognize and respond appropriately to threats such as phishing or social engineering.
What is the difference between a security incident and a security event?
An event is any observable occurrence in a system or network; an incident is an event (or series of events) that violates security policy or threatens the confidentiality, integrity, or availability of an asset.
What are the typical phases of the incident response lifecycle?
Preparation, detection and analysis, containment, eradication, recovery, and post-incident review (lessons learned).
Why is a post-incident review important?
It captures lessons learned to improve detection, response procedures, and controls, reducing the likelihood and impact of similar future incidents.
What is the purpose of a disaster recovery plan (DRP) versus a business continuity plan (BCP)?
The DRP focuses narrowly on restoring IT systems and infrastructure after a disruptive event; the BCP is the broader plan for keeping essential business functions operating during and after a disruption.
What is 'defense in depth'?
A layered security strategy that uses multiple, overlapping controls so that if one control fails, others still protect the asset.
What does the CIA triad stand for in information security?
Confidentiality, Integrity, and Availability — the three core properties that security controls aim to protect.
What is the difference between a threat, a vulnerability, and a risk?
A threat is a potential cause of harm; a vulnerability is a weakness that could be exploited; risk is the likelihood and impact of a threat exploiting a vulnerability.
What is the purpose of a risk register?
A centralized log documenting identified risks, their likelihood and impact, owners, and treatment plans, used to track and manage risk over time.
Name the four common risk treatment options.
Avoid, mitigate (reduce), transfer (share), and accept.
What is chain of custody in incident evidence handling?
The documented, unbroken record of who collected, handled, and stored evidence, ensuring it remains admissible and untampered for investigative or legal purposes.
What is the purpose of a security metrics/dashboard program?
To translate technical security data into business-relevant indicators that demonstrate program effectiveness and support informed decision-making by management.
What is the role of senior management sponsorship in a security program's success?
It provides the authority, funding, and organizational priority needed to enforce policy, allocate resources, and drive cultural adoption of security practices.
What is a tabletop exercise?
A discussion-based simulation where stakeholders walk through an incident or disaster scenario to validate and improve response and recovery plans without disrupting live operations.
Why must security strategy be tied to business objectives rather than technology alone?
Because security exists to enable and protect business value; a strategy disconnected from business goals risks misallocating resources and failing to gain executive support.
CISM glossary
24 terms the CISM tests, defined in plain English.
- Business Continuity Plan (BCP)
- A documented plan for sustaining essential business operations during and after a disruptive event, encompassing more than just IT recovery.
- Business Impact Analysis (BIA)
- A structured process to identify critical business functions and quantify the operational and financial impact of their disruption over time.
- Chain of Custody
- The documented chronological record of evidence handling that preserves its integrity and admissibility during an investigation.
- CIA Triad
- The foundational security model of Confidentiality, Integrity, and Availability that controls are designed to preserve.
- CISM
- Certified Information Security Manager — an ISACA certification for professionals who manage, design, and oversee an enterprise's information security program.
- Defense in Depth
- A security architecture principle that layers multiple independent controls so no single point of failure compromises the entire system.
- Disaster Recovery Plan (DRP)
- A documented plan focused on restoring IT systems, applications, and data after a disruptive event.
- Due Care
- The execution of reasonable, prudent actions to protect an organization's assets and reduce risk.
- Due Diligence
- The ongoing process of investigating and verifying that appropriate controls and precautions are actually in place and functioning.
- Incident Management
- The domain covering the planning, detection, response, and recovery activities used to handle security incidents and minimize their business impact.
- Information Security Governance
- The domain covering the framework of policies, roles, and oversight structures that align an organization's security strategy with its business objectives.
- Information Security Program
- The domain covering the design, implementation, and management of the people, processes, and technology that carry out an organization's security strategy.
- Information Security Risk Management
- The domain covering the identification, analysis, evaluation, and treatment of risks to information assets.
- Key Risk Indicator (KRI)
- A measurable metric that signals rising risk exposure before it results in an adverse event.
- PSI
- The third-party testing vendor ISACA uses to deliver the CISM exam at test centers and via online remote proctoring.
- Residual Risk
- The risk that remains after controls have been implemented to address inherent risk.
- Risk Appetite
- The level and type of risk an organization is willing to accept in pursuit of its objectives, established by senior leadership.
- Risk Register
- A structured record listing identified risks along with their likelihood, impact, owner, and planned treatment.
- Risk Tolerance
- The acceptable variation around risk appetite for a specific objective or metric, defining how much deviation is permissible.
- RPO (Recovery Point Objective)
- The maximum acceptable amount of data loss, measured as a point in time to which data must be recoverable.
- RTO (Recovery Time Objective)
- The maximum tolerable duration within which a business process or system must be restored after a disruption.
- Scaled Score
- A statistically adjusted score, reported on a fixed range such as ISACA's 200-800 scale, that accounts for variation in difficulty across different exam forms.
- Security Steering Committee
- A cross-functional, senior-level governance body that oversees and prioritizes an organization's information security initiatives.
- Tabletop Exercise
- A facilitated, discussion-based walkthrough of a hypothetical incident used to test and refine response plans.
Sources
- 1.CISM Certification Overview — ISACA (accessed Jul 18, 2026)
- 2.CISM Exam Content Outline — ISACA (accessed Jul 18, 2026)
- 3.ISACA Certification Exam Candidate Guide — ISACA (accessed Jul 18, 2026)
- 4.CISA/CRISC/CISM/CGEIT/CDPSE Exam Scheduling Guide — ISACA (accessed Jul 18, 2026)
- 5.ISACA (CISA/CRISC/CISM/CGEIT) Scheduling Guide — PSI (accessed Jul 18, 2026)
Official sources
Primary documents used to verify the exam details shown on this page.
- ISACA Certification Exam Candidate GuideISACAisaca.org
- CISM Exam Content OutlineISACAisaca.org
- CISM Certification OverviewISACAisaca.org
- ISACA (CISA/CRISC/CISM/CGEIT) Scheduling GuidePSIproctor2.psionline.com
- CISA/CRISC/CISM/CGEIT/CDPSE Exam Scheduling GuideISACAisaca.org
Last verified against the ISACA exam content outline: