CISM is a management-focused cybersecurity credential for professionals responsible for security governance, enterprise risk, security programs and incident management. It is especially relevant for security managers, GRC leaders and professionals preparing for director or CISO-level responsibilities.
Exam facts last verified 2026-07-28 against ISACA. Confirm current details at isaca.org before you register.
CISM certifies that you can build, lead and defend an enterprise information security program. The exam is written from the point of view of the manager who owns the outcome rather than the engineer who implements a single control, so most questions ask what a responsible leader should evaluate, decide or escalate first.
The credential sits at the governance and program layer of security work. It assumes you already understand the technology and asks whether you can align it with business objectives, fund it, staff it, measure it and answer for it when something goes wrong.
Establishes the authority, direction and accountability that a security program runs on. This domain is about who decides, on what basis, and how that direction reaches the rest of the organization.
Covers how risk is found, sized, treated and monitored over time. The management emphasis is on ownership and defensible decisions rather than on producing the most elaborate calculation.
The largest domain. It covers building and running the program itself: the roadmap, the resources, the controls, the third parties and the evidence that any of it is working.
Covers readiness, response and recovery. Expect questions that test sequencing and priority under pressure, and that separate the manager's job from the responder's job.
CISM, or Certified Information Security Manager, is a credential from ISACA for professionals who govern and lead information security rather than implement it hands-on. It covers security governance, information security risk management, building and running a security program, and incident management.
It suits information security managers, cybersecurity program managers, GRC managers, security governance leads, cyber-risk managers, consultants and IT managers moving into security leadership. It is also a common step for people preparing for security director or CISO responsibilities.
The exam has 150 multiple-choice questions covering the four CISM domains.
Candidates have 4 hours, which is 240 minutes, to complete the exam.
ISACA lists the exam fee as $575 for ISACA members and $760 for nonmembers, in US dollars. Separately, a one-time $50 certification application fee is paid by every candidate, member or not, at the point of applying for certification after passing. It is not a nonmember surcharge on the exam. Fees change, so confirm current pricing with ISACA before you register.
No. There is no experience prerequisite to sit the exam, and sitting the exam is a separate step from being certified. You cannot hold the certification until you have five years of information security management work experience across at least three of the four domains, gained within the 10 years before you apply. You have five years from your passing date to submit the application.
Yes, up to a point. ISACA allows experience substitutions of up to two years in total against the five-year requirement, earned through qualifying degrees and credentials. The cap is the part people miss: holding several qualifying credentials does not stack beyond two years, and the remaining three years of information security management experience cannot be waived by any route. Confirm the current substitution list with ISACA before you apply.
ISACA allows four attempts in a rolling 12-month period. Waiting periods apply between attempts: 30 days after the first attempt, then 90 days after each attempt that follows. Registering also opens a 12-month eligibility window in which you have to sit the exam.
No. ISACA exams are made up of scored items plus unscored pretest items that do not count toward your result, so you cannot tell your standing from a raw count. The reported score is scaled from 200 to 800 with 450 to pass, and the domain-level breakdown on your score report is informational only rather than part of the pass decision.
Managerial. It assumes technical literacy but tests management judgment: what a responsible leader should evaluate first, who owns a decision, which business objective is at risk and what process produces a defensible result.
Information Security Governance at 17 percent, Information Security Risk Management at 20 percent, Information Security Program at 33 percent, and Incident Management at 30 percent. These weightings apply to exams taken through 2 November 2026. ISACA has announced an updated exam content outline effective 3 November 2026.
None of them is universally better. They answer different questions. CISM is about managing and leading a security program, CISSP covers a broad technical and managerial body of cybersecurity knowledge, and CRISC focuses on technology risk identification, assessment, response and control. Pick the one that matches the role you want next.
It is commonly held by information security managers, cybersecurity program managers, GRC managers, security governance leads, cyber-risk managers, directors of information security, security consultants and CISOs. A credential supports an application; demonstrated program ownership and incident experience carry it.