ISACA Certified Information Security Manager

ISACA · CISM · Expert

ISACA · ISACA

ISACA Certified Information Security Manager

CISMactiveExpert
Official ISACA source · isaca.org

CISM · ● Active · Expert · ISACA


Exam facts

FieldValue
CostUSD $575 (ISACA member) / $760 (non-member); regional pricing varies
Duration4 hours
Questions150 multiple choice
Passing450 / 800 scaled score
FormatMultiple choice
DeliveryPearson VUE testing centers and OnVUE (remote proctored)
LanguagesEnglish (primary); Japanese and other regional languages available
Valid3 years
Renewal120 CPE (Continuing Professional Education) credits within 3-year cycle
Prerequisites5 years cumulative IS security experience with minimum 3 years in IS security management. Substitutions allowed: relevant advanced degree (bachelor's or higher in related field) reduces experience requirement by 1 year; relevant ISACA certification (CISSP, CISM, CAP) reduces by 2 years.
Released2002 (original); current version refreshed continuously per industry evolution
RetiringN/A

Vendor source — ISACA Credentialing ↗ Official exam guide — CISM Candidate Info & Handbook ↗ Exam objectives — CISM Job Practice & Domains ↗


About

The Certified Information Security Manager (CISM) is ISACA's flagship management-level certification for information security leaders. Unlike technical security certs, CISM focuses on governance, risk management, and program oversight — covering security strategy, incident management, and organizational alignment. Originally launched in 2002, CISM is held by over 35,000 professionals globally and is widely recognized as the peer credential to CISSP in enterprise security management contexts. CISM mandates demonstrated professional experience in security management, making it a career-progression credential rather than an entry point.


Domain context — Security / Management

Information security governance and management — directing security programs, managing risk portfolios, aligning security with business outcomes, and leading incident response at the organizational level.

Read full deep dive — ISACA Ecosystem →


Topics covered

CISM covers four knowledge domains, weighted by exam emphasis:

  • Information Security Governance (17%) — Security strategy alignment, organizational structure, policies & standards, compliance frameworks (NIST, ISO 27001, CIS Controls), board/stakeholder reporting.
  • Information Security Risk Management (20%) — Risk identification & assessment, risk appetite/tolerance, threat & vulnerability analysis, risk treatment & mitigation, business continuity planning.
  • Information Security Program Development (33%) — Security program design, resource allocation, metrics & KPIs, security training & awareness, third-party risk management, security architecture oversight.
  • Incident Management (30%) — Incident response planning & preparation, detection & triage, containment & eradication, recovery & restoration, post-incident review, communication & stakeholder management.

Source: ISACA CISM Job Practice ↗


Common skills at Security / Management · Expert

Shared competencies for security management roles at expert level — not specific to CISM.

  • Security program leadership & vision-setting
  • Enterprise risk management & portfolio analysis
  • Compliance & regulatory framework translation (NIST, ISO 27001, SOC 2, HIPAA, PCI-DSS, GDPR)
  • Incident response governance & crisis communication
  • Threat & vulnerability landscape analysis
  • Security metrics, KPIs, and business case building
  • Board-level security briefings & executive reporting

Recommended courses at Security / Management · Expert

ProviderTitleCostURL
ISACA OfficialCISM Online Review Course$600–$800 (member) / $900–$1100 (non-member)
Hemang DoshiISACA CISM Certification All-in-One (Udemy)$15–$100
Phil MartinISACA CISM Exam Preparation (Udemy)$15–$100
Pocket PrepCISM Exam Prep App & Web$50–$100
PluralsightCISM Study Path$300–$500/yr
A Cloud Guru / Linux AcademySecurity Management Path (covers CISM topics)$300–$500/yr

Course-selection rule: CISM is management-focused; courses emphasizing governance, risk frameworks, and incident response leadership are preferred over purely technical security content.


Practice exams

ProviderTitleCostURL
ISACA OfficialCISM Official Practice Questions Database$100–$150 (1,000+ questions)
Pocket PrepCISM Practice Exam Bank$50–$100
BosonCISM ExamREview (120 unique questions, adaptive)$80–$120

Books

TitleAuthorPublisherYearISBNURL
Certified Information Security Manager (CISM) All-in-One Exam GuideHemang DoshiMcGraw-Hill Education2023978-1-260-47509-3
CISM Review Manual (15th Edition)ISACAISACA2024978-1-604-20249-9
CISM Study Guide Exam Questions with Answers & ExplanationsHemang DoshiSelf-published / Udemy2024N/A

Book rule: The ISACA CISM Review Manual is the official reference and essential; Hemang Doshi's All-in-One is widely recommended as a practical study supplement.


Typical job titles at Security / Management · Expert

Information Security Manager · Chief Information Security Officer (CISO) · Senior Security Manager · Director of Information Security · Security Operations Manager · Enterprise Risk Manager

(Job titles drawn from current job-board postings that list CISM as required or preferred.)


Salary

RegionRangeSource
USD$120,000 – $180,000+ for CISM-required roles (Information Security Manager, CISO, Director Security)Glassdoor ↗ · Robert Half 2026 Salary Guide ↗ · Levels.fyi Security Leadership ↗
ZARR1,500,000 – R2,500,000+ annually (security manager tier in South Africa)Pnet ↗ · PayScale ZA Security Manager ↗ · CareerJunction ↗
GBP£80,000 – £130,000+ for CISM-equivalent management roles in UKIT Jobs Watch ↗ · Hays Salary Guide ↗
EUR€90,000 – €140,000+ (Germany/Netherlands security management)LinkedIn Salary EU ↗ · PayScale EU ↗
AUDA$130,000 – A$190,000+ for CISM-level security management in AustraliaSeek ↗ · PayScale AU ↗

Salary note: CISM commands a significant premium over entry-level and mid-level security roles due to the management scope and prerequisite experience. Actual compensation varies by organization size, industry, and geography; CISO roles in regulated industries (finance, healthcare, government) skew higher.


Skills validated

Cert-specific — what CISM actually tests, distinct from the shared "Common skills" above.

  • Security governance frameworks (NIST CSF, ISO 27001, CIS Controls, COBIT)
  • Risk management methodologies & quantitative/qualitative assessment
  • Incident response program design & leadership
  • Compliance mapping (GDPR, HIPAA, PCI-DSS, SOC 2, CMMC)
  • Security metrics, dashboards, and business impact analysis
  • Third-party risk management & vendor assessment
  • Business continuity & disaster recovery planning
  • Security awareness & training program development
  • Board/executive reporting & risk communication
  • Threat landscape & emerging risk trends (AI, supply-chain, cloud)

Related certifications

  • Stacks with: CISSP ↗ (technical focus vs. CISM management focus; often dual-held by enterprise security leaders)
  • Prerequisite for: N/A — CISM is typically a career-progression endpoint, not a stepping stone to a higher cert
  • Equivalent at this level: CISSP ↗ (broader security coverage, technical-leaning; CISM more governance-focused)
  • Vendor overview: ISACA Overview ↗

Sources


Last verified: 2026-05-01 Parent ecosystem: ISACA Ecosystem Parent domain: Security / Management Vendor overview: ISACA Overview

Rate this cert
Was this helpful?
Comments ()
0/2000