What the ISACA CISM is and who it is for
The Certified Information Security Manager is ISACA’s certification for the management and leadership layer of information security. It validates expertise in governance, risk management, security programme development and incident management. It is about deciding what the organisation should do, who owns the decision and how it fits the business. It is widely required for security manager, CISO and IT governance roles.
It is for you if you already manage security work, or you are the technical lead being asked to own policy, budgets, risk registers and incident plans. Full certification needs five years of information security management experience across at least three of the four CISM domains, so check your history against the domains before you commit to a date.
One date matters for your planning: a new exam content outline takes effect on 3 November 2026. If you sit after that date, confirm that your study material matches the new outline.
ISACA CISM at a glance
| Item | Detail |
|---|---|
| Exam code | CISM |
| Questions | 150 |
| Time allowed | 4 hours |
| Passing score | 450 on a scale of 800 |
| Exam fee | US$575 for ISACA members, US$760 for non-members |
| Languages | English, Spanish, Chinese (Simplified), Japanese, French and German |
| Where you sit it | PSI testing centres or remote proctored |
What is on the exam
Four domains. The last two, programme and incident management, make up 63% of the exam between them.
Information security governance (17%). How security is directed from the top: aligning the security strategy with business goals, organisational culture, roles and responsibilities, and the policies, standards and frameworks that turn strategy into rules. Questions here usually ask who should decide, approve or be accountable, and the answer is rarely the security team acting alone.
Information security risk management (20%). Identifying, assessing and treating risk to information assets. You need to be comfortable with risk appetite and tolerance, choosing between accepting, mitigating, transferring and avoiding a risk, and keeping the risk register current. ISACA wants risk decisions tied to business impact, not to how serious a vulnerability sounds.
Information security program (33%). The largest domain. It covers building and running the security programme: resources, controls, architecture, awareness and training, third party and vendor security, and metrics that show whether the programme is working. Many questions describe a new manager inheriting a situation and ask what they should do first.
Incident management (30%). Preparing for, responding to and recovering from incidents, and the business continuity and disaster recovery planning that sits alongside them. Expect questions on incident response plans, escalation, communication, testing plans and what the priority is at each stage of an incident.
Why people fail it
CISM is a management and governance exam that tests judgement, not configuration skills. That catches out strong technical candidates. Practice labs do not help much here. The trap is getting a question wrong because your security concept was correct but your management framing was not. A technically sound answer that skips business alignment, senior management approval or the risk owner is usually the wrong one.
The second problem is the “best” and “first” question. Several options will be reasonable things a security manager might do. Only one is the thing ISACA expects to happen first or to matter most, and that is usually the one that involves understanding the business, assessing the risk or following the governance structure before acting. Candidates who answer from their own organisation’s habits can pick defensible options that are not the ones being marked.
Third, the cost. Every failed attempt costs the full fee again, with no discount for a second try, and the eligibility bar of five years of management experience means most candidates are sitting it with a busy job on top. Finally, weighting: programme and incident management together are 63% of the exam, and people who spend most of their time on governance because it feels like the heart of the certification leave the heavier domains thin.
A study plan that fits the exam
Seven weeks, weighted by domain: two weeks each for the two largest domains, one each for governance and risk, and a final week of timed practice. If you sit after 3 November 2026, check each week’s material against the new outline.
- Week 1: governance. Strategy, culture, roles and responsibilities, policies and frameworks. At the end of the week, try the free CISM practice questions to get a feel for ISACA’s management framing.
- Week 2: risk management. Assessment, treatment options, appetite and tolerance, and the risk register. Practise explaining each decision in terms of business impact.
- Week 3: security programme, part one. Programme development, resources, controls and architecture. Work the programme questions in the CISM practice question pack and read every explanation, including the wrong options.
- Week 4: security programme, part two. Awareness, third party security, metrics and reporting. Then a mixed set of questions across the first three domains.
- Week 5: incident management, part one. Incident response planning, roles, escalation and communication.
- Week 6: incident management, part two. Business continuity, disaster recovery and plan testing. Finish with a mixed set across all four domains.
- Week 7: timed runs. Use the questions only PDF for full sittings of 150 questions in 4 hours, score yourself by domain, and spend the remaining days on the weakest one.
On exam day
You sit CISM at a PSI testing centre or remote proctored. For remote delivery, check the room, desk and webcam rules in advance and run the system check on the computer you will use. For a centre, bring the identification your booking lists and arrive early. The exam is available in English, Spanish, Chinese (Simplified), Japanese, French and German, so choose the language you read most carefully in.
You have 4 hours for 150 questions, which is enough if you keep moving. When two answers both look right, ask which one a manager answerable to the board would choose, and prefer the one that follows governance and risk process. The passing score is 450 on a scale of 800, and the scale is not a straight percentage, so do not try to count marks as you go.
Frequently asked questions
What happens if I fail? Can I retake it?
You can, but each attempt costs the full fee again, currently US$575 for members and US$760 for non-members, with no discount for a second try. ISACA publishes its retake rules, including any limits on attempts, on its website, so read them before you book. The practice pack is refunded if you fail, but the exam fee is not.
Does the November 2026 outline change affect me?
Only if you sit on or after 3 November 2026. In that case, make sure the material you study from reflects the new content outline, and check the domain list on the ISACA site before you plan your weeks.
Can I sit the exam before I have five years of experience?
The five years of information security management experience, across at least three of the four domains, is the requirement for full certification. ISACA sets out how and when that experience must be shown on its website, so check the current rules there before you book.
Is the practice question pack enough on its own?
No. It is 1,250 practice questions with an explanation for every answer and every wrong option, and its real value is making ISACA’s management framing familiar. It is practice, not a course. It will not replace a review manual or your own management experience. Use it alongside your study material to test your judgement and find your weakest domain.
When you are ready to test your judgement, get the 1,250 question CISM pack for US$39, pass or your money back.
