Examers.io
ExamsOrganizationsHow it worksPricingHelp & FAQ
ISACA

Certified Information Security Manager

The Certified Information Security Manager (CISM) certification validates your expertise in information security governance, risk management, program development, and incident management. Designed for mid-to-advanced career IT professionals aspiring to senior management roles, CISM demonstrates your ability to align security programs with business goals and lead enterprise security initiatives. Earning CISM signals to employers that you can assess risks, implement effective governance, and proactively respond to incidents, making you a trusted leader in the field.

Exam formatComputer-based
DeliveryPSI
Free questions538

Content last reviewed 30 July 2026 · Up to date

The certification

What Certified Information Security Manager proves, and what it asks of you

What this certification covers, who it is written for, and what the exam itself looks like on the day.

4domains
18objectives
128concepts
US $575exam fee
What it is

What this certification is

What it validates, who it is written for, and the experience it assumes.

About this certification

The Certified Information Security Manager (CISM) certification is ISACA's premier credential for information security management. It affirms your ability to assess risks, implement effective governance, and proactively respond to incidents, with a focus on emerging technologies such as AI and blockchain. CISM ensures your skillset meets evolving security threats and industry requirements, addressing top-of-mind concerns like data breaches and ransomware attacks.

Earning CISM demonstrates your proficiency in managing and overseeing information security programs, from developing strategy to executing incident response. The certification is globally recognized and required by many organizations and government agencies, providing you with the credibility to advance your career and add value to your enterprise.

Who it’s for

This certification is for mid-to-advanced career IT professionals who aspire to senior management roles in IT security and control. It is ideal for those responsible for designing, implementing, and managing enterprise information security programs, including security managers, IT consultants, and aspiring CISOs. CISM is designed for professionals who want to validate their expertise in information security governance, risk management, program development, and incident management, and who are ready to take on leadership responsibilities in the field.

Recommended experience

While there are no formal prerequisites, ISACA recommends that candidates have a minimum of five years of experience in information security management, with at least three years in the specific job practice areas covered by the exam. Experience in information security governance and strategy; Experience in information security risk management; Experience in developing and managing information security programs; Experience in incident management and response

The syllabus

What you’ll learn

Every domain and objective ISACA measures, with the weight they carry on the exam.

The official ISACA exam outline · checked 30 July 2026 · See the source

Domain 1: Information Security Governance
  • Organizational Culture
  • Legal, Regulatory and Contractual Requirements
  • Organizational Structures, Roles and Responsibilities
  • Information Security Strategy Development
  • Information Governance Frameworks and Standards
  • Strategic Planning (Budgets, Resources, Business Case)
6 objectives · 156 free questions · 34 pages
Domain 2: Information Security Risk Management
  • Emerging Risk and Threat Landscape
  • Vulnerability and Control Deficiency Analysis
  • Risk Assessment and Analysis
  • Risk Treatment / Risk Response Options
  • Risk and Control Ownership
  • Risk Monitoring and Reporting
6 objectives · 194 free questions · 40 pages
Domain 3: Information Security Program
  • Program Foundation and Governance
  • Program Implementation and Operations
  • Program Communication and External Management
3 objectives · 99 free questions · 21 pages
Domain 4: Incident Management
  • Preparation
  • Response
  • Post-Incident Activity
3 objectives · 89 free questions · 19 pages
On the day

The exam itself

Everything ISACA publishes about sitting it, and nothing we inferred.

Prerequisites

Pass the CISM certification exam.

CertificationCertified Information Security Manager
Exam formatComputer-based
DeliveryPSI
LanguagesEnglish, Chinese Simplified, Japanese, Spanish
PricingUS $575
After you pass

Where this credential goes next

The path ISACA lays out, how the credential is kept, and where to book.

Step-by-step path to Certified Information Security Manager

PrerequisitePass the CISM certification exam.
Certified Information Security Manager badgeCredential earnedCertified Information Security Manager Certification
Renewal and maintenance

CISM certification must be maintained annually by earning and reporting Continuing Professional Education (CPE) credits, as outlined in ISACA's Continuing Professional Education Policy. Stay current with the latest technologies and maintain your certification.

Learn more about renewal requirements
Lifecycle status

This certification is currently active and available. ISACA maintains this certification to validate current skills and industry relevance.

Exam status: ActiveMaintained by ISACA

Exam registration

Register for the exam through PSI, ISACA’s authorized testing partner.

Schedule your exam

Visit the official ISACA certification page for exam policies and requirements.

View the official page
Your coach

And when you are serious, your coach Pip takes over

Your coach in the app reads what you have answered with the book closed and tells you one thing to do tonight. It will not count an answer you gave with the page open, and it will tell you when you are not ready.

See how the coach works
Before you book

Questions people ask

How does the CISM exam relate to the upcoming exam content outline update?

The CISM Exam Content Outline will be updated effective 3 November 2026. Starting on that date, the exam will reflect the new outline. Updated preparation materials will be available for purchase in September 2026. Purchasing current material will not grant access to the newer material later.

Is there a higher-level certification that requires CISM as a prerequisite?

Yes, ISACA's Advanced in AI Security Management (AAISM) certification requires candidates to hold an active CISM or CISSP certification. This advanced credential focuses on AI-specific security issues and builds upon existing security management best practices.

Can I reschedule my CISM exam appointment?

Yes, you can reschedule your CISM exam anytime without penalty during your eligibility period, provided you do so at least 48 hours prior to your scheduled testing appointment. Log in to your ISACA Account and follow the rescheduling steps in the Scheduling Guide.

What are the identification requirements for the CISM exam?

You must present a valid government-issued identification that matches the name on your ISACA account. Ensure your name matches what appears on your government-issued ID when creating your account.

Is there a retake policy for the CISM exam?

ISACA has a zero-tolerance policy for fraudulent test-taking activities. Candidates involved in fraudulent activities will be subject to score nullification and/or certification revocation. Specific retake waiting periods are not published on the official page.

Are there any hands-on or lab components in the CISM exam?

The CISM exam is computer-based and consists of multiple-choice questions. There is no hands-on or lab component mentioned in the official materials.

What job roles does the CISM certification map to?

CISM is designed for mid-to-advanced career IT professionals aspiring to senior management roles in IT security and control, such as information security managers, IT consultants, and aspiring CISOs.

Can I recertify by passing a different ISACA exam?

ISACA certifications require renewal through earning CPE credits. Passing a different exam may contribute to CPE credits, but there is no automatic recertification by passing another exam.

Is the CISM exam available in all countries?

The CISM exam is administered at authorized PSI testing centers globally or as remotely proctored exams. However, some regions may have restrictions on remote proctoring; for example, the AAISM exam is exclusively available at testing centers in India, Mainland China, and Hong Kong.

Information freshness · Content last reviewed on 2026-07-30 Up to date
Practice free questions 538 questions, free, no account needed.