ISACA

CISM

Certified Information Security Manager

Management-focused information security certification for security managers, directors, and CISOs. Commonly required or preferred for security leadership roles and carries a strong wage premium.

$5754 hours
or go All-Access →

Blueprint-complete program: 4 decks, 805 cards.

What's on the exam

CISM Exam Content Outline (effective 1 June 2022)

Information Security Governance

17%

Governance frameworks and strategy · Organizational culture and structure · Legal and regulatory requirements · Roles and responsibilities · Aligning security with business goals

Information Security Risk Management

20%

Risk identification and assessment · Risk analysis and evaluation · Risk treatment and response options · Risk monitoring and reporting · Asset classification and valuation

Information Security Program

33%

Program development and resources · Security control design and implementation · Awareness and training · Metrics and program management · Third-party and vendor management

Incident Management

30%

Incident response planning · Detection and classification · Containment, eradication, and recovery · Business continuity and disaster recovery · Post-incident review and forensics

Frequently asked questions

How much does the CISM cost?

The CISM costs $575. US$575 for ISACA members, US$760 for non-members; plus a one-time application fee for certification.

How long is the CISM and how many questions does it have?

150 items — 4 hours.

What do you need to pass the CISM?

450 on a scale of 200–800.

Can you retake the CISM?

Up to 4 attempts per 12-month period.

What is the best way to study for the CISM?

Study the official blueprint, not random material: the exam is weighted by domain (Information Security Governance 17%, Information Security Risk Management 20%, Information Security Program 33%, Incident Management 30%). Spaced-repetition flashcards built domain-by-domain against that blueprint are the most time-efficient way to cover everything the exam tests.

Ready to prepare?

Our CISM — Certified Information Security Manager program follows this exact blueprint — every domain covered, scheduled by spaced repetition, with a journey from first card to test day.

or go All-Access →

See what's inside →