CISM

CISM

Offered by ISACA

Certified Information Security Manager (CISM) from ISACA is a management-focused security credential. Rather than hands-on technical depth, it validates...

Sign up or log in to unlock peer-created videos, posts, private forums, and study groups.

Be the first

Nobody has started a CISM study group or listed as a tutor yet. If you’re preparing for this exam, start the group — the next person who lands here will have somewhere to study with you.

Start the first study group

Already hold CISM? Become the first tutor

Not ready to host?

We’ll email you when someone else starts a CISM group.

CISM exam at a glance

Format

150 multiple-choice questions (4 options, one best answer)

Duration

240 minutes (4 hours)

Delivery

PSI test center or online remote proctored

Passing score

450 on a scale of 200–800 (scaled)

Exam cost

$575 (ISACA member) / $760 (non-member), USD, plus a $50 application fee to certify

Validity

3 years; maintain with 120 CPE hours (20/year)

Prerequisites

5 years of information security management experience in 3+ of the 4 domains (up to 2 years waivable); can be earned within 5 years of passing

About the CISM certification

Certified Information Security Manager (CISM) from ISACA is a management-focused security credential. Rather than hands-on technical depth, it validates the ability to build and govern an enterprise information security program, manage risk, and lead incident response.

It's highly valued for security-management and CISO-track roles and consistently commands strong salaries.

Who it’s for: Security managers, aspiring CISOs, and experienced practitioners moving into leadership.

Official exam page· Details verified 2026-08

What the CISM exam covers
  • Information Security Governance
    17%
  • Information Security Risk Management
    20%
  • Information Security Program
    33%
  • Incident Management
    30%
How to study for the CISM
  1. 1Study ISACA's four job-practice domains, prioritizing Program (33%) and Incident Management (30%).
  2. 2Learn to answer from a manager's perspective, aligning security with business goals.
  3. 3Use the ISACA review manual and question database.
  4. 4Practice scenario questions on governance, risk, and incident response.
  5. 5Document your qualifying experience for the certification application after passing.
CISM — frequently asked questions

Is CISM technical?

Less than CISSP. CISM focuses on managing and governing security programs rather than hands-on implementation.