GRC Careers Academy · Module

CISM

Certified Information Security Manager
Senior-Level Certification · ISACA
SHARE: LinkedIn X Facebook Email Copy link

CISM is a management-focused cybersecurity credential for professionals responsible for security governance, enterprise risk, security programs and incident management. It is especially relevant for security managers, GRC leaders and professionals preparing for director or CISO-level responsibilities.

CISM certifies that you can build, lead and defend an enterprise information security program. The exam is written from the point of view of the manager who owns the outcome rather than the engineer who implements a single control, so most questions ask what a responsible leader should evaluate, decide or escalate first.

The credential sits at the governance and program layer of security work. It assumes you already understand the technology and asks whether you can align it with business objectives, fund it, staff it, measure it and answer for it when something goes wrong.

Study tool CISM Flashcards → 44 cards across all four domains. Flip, self-rate, and track what you know. Free.

Inside This Module — The Four Domains

Domain 117%

Information Security Governance

Establishes the authority, direction and accountability that a security program runs on. This domain is about who decides, on what basis, and how that direction reaches the rest of the organization.

  • Governance frameworks and operating models
  • Information security strategy and its alignment to business objectives
  • Organizational roles, responsibilities and accountability
  • Policies, standards and supporting documentation
  • Legal, regulatory and contractual requirements
  • Risk appetite and risk tolerance
Domain 220%

Information Security Risk Management

Covers how risk is found, sized, treated and monitored over time. The management emphasis is on ownership and defensible decisions rather than on producing the most elaborate calculation.

  • Risk identification and threat and vulnerability analysis
  • Risk assessment and risk analysis methods
  • Risk treatment options and selection
  • Risk ownership and accountability
  • Risk acceptance and formal exceptions
  • Inherent risk and residual risk
Domain 333%

Information Security Program

The largest domain. It covers building and running the program itself: the roadmap, the resources, the controls, the third parties and the evidence that any of it is working.

  • Program development and operating structure
  • Program roadmaps and prioritization
  • Resource, budget and staffing management
  • Security control selection and implementation
  • Metrics, measurement and management reporting
  • Third-party and supply-chain risk
Domain 430%

Incident Management

Covers readiness, response and recovery. Expect questions that test sequencing and priority under pressure, and that separate the manager's job from the responder's job.

  • Incident-management planning and readiness
  • Detection and analysis
  • Classification and escalation
  • Containment, eradication and recovery
  • Crisis communication and stakeholder notification
  • Business continuity planning

Core Concepts You'll Master

The CISM exam is designed to test management judgment. Candidates should evaluate questions from the perspective of the person responsible for governing risk, directing a security program and protecting the organization's business objectives.

Governance

[object Object]

Risk Management

[object Object]

Frameworks

Incident Response Lifecycle

Metrics & Reporting

[object Object]

Security Leadership

Exam at a Glance

Questions150
Duration4 hours
FormatMultiple choice
Passing score450 on a scaled range of 200 to 800
Experience requiredFive years of information security management work experience, across at least three of the four CISM domains.
Download the CISM Reference & Study Guide
Volume I — the full exam-at-a-glance, all four domains, and the study essentials, in one branded PDF.
Get the PDF →

Get notified when new Academy modules launch

New certification modules, study resources, and GRC career guides — the moment they're ready.

Unsubscribe anytime, one click. We never share your details.

Where CISM Takes You

CISM supports these roles, but it does not by itself qualify anyone for them. Hiring for security leadership weighs demonstrated program ownership, incident experience and executive communication alongside credentials.

CISM and ISACA are trademarks of ISACA. GRC-Careers.org is not affiliated with, endorsed by or accredited by ISACA. This page is an independent study aid and contains no real exam questions.
Exam facts, fees, experience requirements and maintenance requirements on this page were verified against ISACA's published pages on the date shown. Credential level, study priorities and the incident-priority ordering are GRC Careers' editorial classifications rather than ISACA designations. Fees and exam requirements change. Confirm current information with ISACA before you register.
This is an original GRC Careers Academy module. It contains no real exam questions.