ISACA CISM Certification

Certification guide

The Certified Information Security Manager (CISM) is ISACA’s credential for the people who run security as a business function, the managers, directors, and aspiring CISOs accountable for governance, risk decisions, program delivery, and incident leadership. Where technical certifications ask whether you can configure a control, the CISM asks whether you can decide which controls are worth their cost, who should own the risk they leave behind, and how to explain all of it to a board. Since 2002 it has been one of the most consistently demanded credentials for security leadership roles, and it pairs naturally with ISACA’s audit-side CISA.

That framing shapes how the exam is written. CISM questions are notorious for offering four answers that are all technically defensible, the exam rewards the one that is most correct from a senior management perspective: understand the business objective first, identify who owns the decision, follow the governance process, and weigh cost against impact. Candidates who jump straight to the technical fix, skip the accountable owner, or accept risk on the business’s behalf lose points to candidates who think like managers. Every question in our banks is built to exercise exactly that judgment.

One scheduling note: ISACA has announced that an updated CISM Exam Content Outline takes effect on November 3, 2026. Exams taken before that date test the current four-domain outline shown below, which has been in force since June 2022; exams on or after it test the revised outline. If you are studying now against the current outline, plan to sit the exam, with buffer for ISACA’s 30-day retake wait, before the cutover.

Exam: CISM · ISACA 150 questions · multiple choice 4 hours (240 min) Scored 200-800 · pass 450 4 domains $575 member / $760 non-member PSI centers or remote proctored 5 yrs experience · waivers up to 2

Information Security Governance

Domain 1 · 17%

How security is directed and held accountable at the enterprise level: aligning the security strategy with business objectives, establishing the governance framework, defining roles from the board and steering committee down to owners and custodians, navigating organizational culture and legal obligations, and building the business cases and board-level metrics that keep the program funded and credible.

Information Security Risk Management

Domain 2 · 20%

Identifying, analyzing, and treating information risk in business terms: the emerging threat landscape, vulnerability and control-deficiency analysis, qualitative and quantitative assessment, risk appetite and tolerance, the four treatment options, risk and control ownership, and the monitoring and reporting (risk registers, KRIs, escalation of residual risk) that keep exposure visibly inside what the business has agreed to accept.

Information Security Program

Domain 3 · 33%

The heaviest domain, covering how a security program is built and operated: asset identification and classification, standards and frameworks, the policy hierarchy, program metrics, control design, selection, implementation, and testing, security awareness and role-based training, management of external and cloud services, and communicating program performance to stakeholders, the day-to-day machinery a security manager is actually judged on.

Incident Management

Domain 4 · 30%

Readiness and operations for the day something goes wrong: incident response planning, business impact analysis, continuity and disaster recovery integration, classification and escalation criteria, exercising and testing, and the operational sequence (triage, containment, eradication, recovery, and post-incident review) along with evidence handling, notification obligations, and communicating through a crisis.

Our CISM practice exams mirror the real thing: 150 questions per set, drawn to the official domain weights above, on a 240-minute timer. ISACA scores the live exam on a scaled 200-800 range with 450 to pass. A conversion that is deliberately non-linear, so no fixed percentage maps exactly to it. We set the pass mark on our sets at 65%, an honest raw-score equivalent of where the 450 threshold tends to land, and because every set is stratified to the official weights, clearing it means you performed across all four domains, not luck in the heavy ones. With Domains 3 and 4 together carrying 63% of the exam, that stratification is the difference between a practice score that predicts and one that flatters.

ISACA CISM - Practice Exam

150-question CISM practice exam aligned to the current ISACA CISM Exam Content Outline. Time limit 240 minutes; pass mark 65% (honest raw-score equivalent of 450/800).

150 questions 240 min pass 65%
Subscribe to start

Each question includes a full explanation of why the best answer beats the near-miss options, the exact judgment the CISM tests. Work a set under the timer, review every explanation including the ones you got right, and let your per-domain results tell you where to spend your remaining study time.

Frequently asked questions about CISM

What is the CISM certification?

The Certified Information Security Manager (CISM) is ISACA’s credential for people who run security as a business function, managers, directors, and aspiring CISOs accountable for governance, risk decisions, program delivery, and incident leadership. Rather than asking whether you can configure a control, it asks whether you can decide which controls are worth their cost, who owns the residual risk, and how to explain that to a board.

How many questions are on the CISM exam and how long is it?

The exam is 150 multiple-choice questions delivered in 4 hours (240 minutes). It is available at PSI test centers or via remote proctoring.

What is the passing score for CISM?

ISACA scores CISM on a scaled range of 200-800, with 450 required to pass. The conversion is deliberately non-linear, so no fixed raw percentage maps exactly to it, which is why our practice sets use 65% as an honest raw-score equivalent of where the 450 threshold tends to land.

How much does the CISM exam cost?

Registration is $575 for ISACA members and $760 for non-members.

What experience do I need to sit for CISM?

CISM requires five years of information security work experience, with waivers available for up to two of those years. Verify the current eligibility rules and waiver categories at isaca.org before you apply.

What domains does CISM cover and how are they weighted?

Four domains: Information Security Governance (17%), Information Security Risk Management (20%), Information Security Program (33%), and Incident Management (30%). Domains 3 and 4 together carry 63% of the exam, so they should absorb the largest share of your study time.

How hard is the CISM exam?

The difficulty is less about recall than about judgment. CISM questions are known for offering four answers that are all technically defensible; the exam rewards the one that is most correct from a senior management perspective, understand the business objective first, identify who owns the decision, follow the governance process, and weigh cost against impact. Candidates who reach for the technical fix, skip the accountable owner, or accept risk on the business’s behalf lose points to candidates who think like managers.

How soon can I retake CISM if I fail?

ISACA imposes a 30-day wait between attempts. If you are timing your sitting against the November 3, 2026 outline change, build that retake window into your schedule so a first-attempt miss does not push you past the cutover.

How should I prepare for the CISM exam?

Practice against the real shape of the exam. Certifym’s CISM sets run 150 questions on a 240-minute timer and are stratified to the official domain weights, so clearing the 65% pass mark means you performed across all four domains rather than getting lucky in the heavy ones. Work a set under the timer, review every explanation, including the questions you got right, and let your per-domain results direct your remaining study time.

What is the difference between CISM and CISA?

They are the two halves of ISACA’s core practice. CISM is the management side, governance, risk decisions, program delivery, and incident leadership for the person accountable for security. CISA is the audit and assurance side, for practitioners who evaluate whether those controls actually work and render defensible conclusions about them. The two pair naturally, and many security leaders hold both.

Trademark notice & independence. Certifym.net is operated by Certifym Exam Services, LLC and is not affiliated with, endorsed by, or sponsored by ISACA. CISM® and CISA® are registered trademarks of ISACA (Information Systems Audit and Control Association). Use of these marks is solely to identify the certification for which these study materials are intended. The CISM Exam Content Outline and its domain structure are the property of ISACA; candidates should download the official, current exam content outline directly from isaca.org.

All questions, answers, and explanations on Certifym are original content created for practice purposes. They are not actual ISACA examination questions and are not represented as such. Practicing with these materials does not guarantee a passing result on any live certification exam. Exam requirements, format, domain weights, and eligibility criteria are set by ISACA and may change (including the announced November 3, 2026 outline update) so always verify current details at isaca.org before scheduling your exam.