CISM · ● Active · Expert · ISACA
Exam facts
| Field | Value |
|---|---|
| Cost | USD $575 (ISACA member) / $760 (non-member); regional pricing varies |
| Duration | 4 hours |
| Questions | 150 multiple choice |
| Passing | 450 / 800 scaled score |
| Format | Multiple choice |
| Delivery | Pearson VUE testing centers and OnVUE (remote proctored) |
| Languages | English (primary); Japanese and other regional languages available |
| Valid | 3 years |
| Renewal | 120 CPE (Continuing Professional Education) credits within 3-year cycle |
| Prerequisites | 5 years cumulative IS security experience with minimum 3 years in IS security management. Substitutions allowed: relevant advanced degree (bachelor's or higher in related field) reduces experience requirement by 1 year; relevant ISACA certification (CISSP, CISM, CAP) reduces by 2 years. |
| Released | 2002 (original); current version refreshed continuously per industry evolution |
| Retiring | N/A |
Vendor source — ISACA Credentialing ↗ Official exam guide — CISM Candidate Info & Handbook ↗ Exam objectives — CISM Job Practice & Domains ↗
About
The Certified Information Security Manager (CISM) is ISACA's flagship management-level certification for information security leaders. Unlike technical security certs, CISM focuses on governance, risk management, and program oversight — covering security strategy, incident management, and organizational alignment. Originally launched in 2002, CISM is held by over 35,000 professionals globally and is widely recognized as the peer credential to CISSP in enterprise security management contexts. CISM mandates demonstrated professional experience in security management, making it a career-progression credential rather than an entry point.
Domain context — Security / Management
Information security governance and management — directing security programs, managing risk portfolios, aligning security with business outcomes, and leading incident response at the organizational level.
Read full deep dive — ISACA Ecosystem →
Topics covered
CISM covers four knowledge domains, weighted by exam emphasis:
- Information Security Governance (17%) — Security strategy alignment, organizational structure, policies & standards, compliance frameworks (NIST, ISO 27001, CIS Controls), board/stakeholder reporting.
- Information Security Risk Management (20%) — Risk identification & assessment, risk appetite/tolerance, threat & vulnerability analysis, risk treatment & mitigation, business continuity planning.
- Information Security Program Development (33%) — Security program design, resource allocation, metrics & KPIs, security training & awareness, third-party risk management, security architecture oversight.
- Incident Management (30%) — Incident response planning & preparation, detection & triage, containment & eradication, recovery & restoration, post-incident review, communication & stakeholder management.
Source: ISACA CISM Job Practice ↗
Common skills at Security / Management · Expert
Shared competencies for security management roles at expert level — not specific to CISM.
- Security program leadership & vision-setting
- Enterprise risk management & portfolio analysis
- Compliance & regulatory framework translation (NIST, ISO 27001, SOC 2, HIPAA, PCI-DSS, GDPR)
- Incident response governance & crisis communication
- Threat & vulnerability landscape analysis
- Security metrics, KPIs, and business case building
- Board-level security briefings & executive reporting
Recommended courses at Security / Management · Expert
| Provider | Title | Cost | URL |
|---|---|---|---|
| ISACA Official | CISM Online Review Course | $600–$800 (member) / $900–$1100 (non-member) | ↗ |
| Hemang Doshi | ISACA CISM Certification All-in-One (Udemy) | $15–$100 | ↗ |
| Phil Martin | ISACA CISM Exam Preparation (Udemy) | $15–$100 | ↗ |
| Pocket Prep | CISM Exam Prep App & Web | $50–$100 | ↗ |
| Pluralsight | CISM Study Path | $300–$500/yr | ↗ |
| A Cloud Guru / Linux Academy | Security Management Path (covers CISM topics) | $300–$500/yr | ↗ |
Course-selection rule: CISM is management-focused; courses emphasizing governance, risk frameworks, and incident response leadership are preferred over purely technical security content.
Practice exams
| Provider | Title | Cost | URL |
|---|---|---|---|
| ISACA Official | CISM Official Practice Questions Database | $100–$150 (1,000+ questions) | ↗ |
| Pocket Prep | CISM Practice Exam Bank | $50–$100 | ↗ |
| Boson | CISM ExamREview (120 unique questions, adaptive) | $80–$120 | ↗ |
Books
| Title | Author | Publisher | Year | ISBN | URL |
|---|---|---|---|---|---|
| Certified Information Security Manager (CISM) All-in-One Exam Guide | Hemang Doshi | McGraw-Hill Education | 2023 | 978-1-260-47509-3 | ↗ |
| CISM Review Manual (15th Edition) | ISACA | ISACA | 2024 | 978-1-604-20249-9 | ↗ |
| CISM Study Guide Exam Questions with Answers & Explanations | Hemang Doshi | Self-published / Udemy | 2024 | N/A | ↗ |
Book rule: The ISACA CISM Review Manual is the official reference and essential; Hemang Doshi's All-in-One is widely recommended as a practical study supplement.
Typical job titles at Security / Management · Expert
Information Security Manager · Chief Information Security Officer (CISO) · Senior Security Manager · Director of Information Security · Security Operations Manager · Enterprise Risk Manager
(Job titles drawn from current job-board postings that list CISM as required or preferred.)
Salary
| Region | Range | Source |
|---|---|---|
| USD | $120,000 – $180,000+ for CISM-required roles (Information Security Manager, CISO, Director Security) | Glassdoor ↗ · Robert Half 2026 Salary Guide ↗ · Levels.fyi Security Leadership ↗ |
| ZAR | R1,500,000 – R2,500,000+ annually (security manager tier in South Africa) | Pnet ↗ · PayScale ZA Security Manager ↗ · CareerJunction ↗ |
| GBP | £80,000 – £130,000+ for CISM-equivalent management roles in UK | IT Jobs Watch ↗ · Hays Salary Guide ↗ |
| EUR | €90,000 – €140,000+ (Germany/Netherlands security management) | LinkedIn Salary EU ↗ · PayScale EU ↗ |
| AUD | A$130,000 – A$190,000+ for CISM-level security management in Australia | Seek ↗ · PayScale AU ↗ |
Salary note: CISM commands a significant premium over entry-level and mid-level security roles due to the management scope and prerequisite experience. Actual compensation varies by organization size, industry, and geography; CISO roles in regulated industries (finance, healthcare, government) skew higher.
Skills validated
Cert-specific — what CISM actually tests, distinct from the shared "Common skills" above.
- Security governance frameworks (NIST CSF, ISO 27001, CIS Controls, COBIT)
- Risk management methodologies & quantitative/qualitative assessment
- Incident response program design & leadership
- Compliance mapping (GDPR, HIPAA, PCI-DSS, SOC 2, CMMC)
- Security metrics, dashboards, and business impact analysis
- Third-party risk management & vendor assessment
- Business continuity & disaster recovery planning
- Security awareness & training program development
- Board/executive reporting & risk communication
- Threat landscape & emerging risk trends (AI, supply-chain, cloud)
Related certifications
- Stacks with: CISSP ↗ (technical focus vs. CISM management focus; often dual-held by enterprise security leaders)
- Prerequisite for: N/A — CISM is typically a career-progression endpoint, not a stepping stone to a higher cert
- Equivalent at this level: CISSP ↗ (broader security coverage, technical-leaning; CISM more governance-focused)
- Vendor overview: ISACA Overview ↗
Sources
- ISACA Credentialing — https://www.isaca.org/credentialing/cism
- ISACA CISM Candidate Handbook & Exam Details — https://www.isaca.org/credentialing/cism
- CISM Review Manual (15th Edition) — https://www.isaca.org/credentialing/cism
- ISACA Official Practice Questions Database — https://www.isaca.org/credentialing/cism
- Robert Half 2026 Salary Guide — https://www.roberthalf.com
- Levels.fyi Security Leadership Roles — https://www.levels.fyi
- Glassdoor CISM Salary Data — https://www.glassdoor.com
- IT Jobs Watch UK Salary Data — https://www.itjobswatch.co.uk
Last verified: 2026-05-01 Parent ecosystem: ISACA Ecosystem Parent domain: Security / Management Vendor overview: ISACA Overview