Skip to main content
← Back to certifications
ISACAGRC and AuditAdvancedVendor-neutralActive

ISACA CISM

A security-management credential centered on governance, risk management, security program development, security operations, and incident-management leadership.

Last verified: 2026-09-01

Overview

ISACA CISM (Certified Information Security Manager) is an advanced, vendor-neutral certification for professionals who manage, design, oversee, and assess enterprise information security programs. It emphasizes the management and governance side of cybersecurity rather than hands-on technical administration, with a strong focus on aligning security strategy with business goals, managing information security risk, building and operating security programs, and leading incident management activities.\n\nCISM is well suited to experienced security professionals moving into leadership, governance, risk, or program-management responsibilities. The credential is commonly associated with roles that require translating technical security concerns into business risk decisions, establishing security governance, directing security programs, and coordinating organizational response to security incidents.\n\nAs of September 2026, the active CISM exam uses four job-practice domains. ISACA has announced that an updated CISM exam content outline will take effect on November 3, 2026, so candidates planning to test after that date should review the new official outline before preparing.

Recommended experience
The CISM exam is open to anyone, but earning the certification requires at least five years of professional information security management experience within the CISM job-practice areas. ISACA states that candidates should have experience across at least three of the four CISM domains, and the required experience must generally fall within the 10 years preceding the certification application. Candidates have five years after passing the exam to apply for certification. Current ISACA policy allows qualifying substitutions or waivers for up to two years of the experience requirement.
Estimated study time
100–160 hours
Target job roles
Information Security ManagerCybersecurity ManagerSecurity Program ManagerInformation Security OfficerGRC ManagerSecurity Risk ManagerSecurity Consultant

Exam Details

CISM Certification Exam

Exam code
CISM
Number of exams
1
Duration
240 minutes
Question count
150 multiple-choice questions
Delivery method
Authorized PSI testing center or remotely proctored exam
Price
$575 USD for ISACA members; $760 USD for non-members

Skills and Domains

Information Security Governance

17%

Covers enterprise governance and information security strategy, including organizational structures, legal and regulatory requirements, governance frameworks, strategic planning, resources, and alignment of security with business objectives.

Information Security Risk Management

20%

Covers identifying, assessing, responding to, monitoring, and communicating information security risk, including emerging threats, vulnerabilities, control deficiencies, risk ownership, and treatment decisions.

Information Security Program

33%

Covers development and management of an enterprise information security program, including resources, asset classification, policies, standards, controls, testing, awareness, third-party services, metrics, and reporting.

Incident Management

30%

Covers incident-management readiness and operations, including response planning, business impact analysis, continuity and disaster recovery, incident classification, training, investigation, containment, recovery, communications, and post-incident improvement.

Study Resources

ISACA CISM Certification

Official resource

Documentation · Free

Official CISM certification overview, registration information, pricing, preparation links, and certification process.

View resource

CISM Exam Content Outline

Official resource

Official Guide · Free

Official ISACA CISM exam domains, weights, job-practice areas, and exam-content guidance.

View resource

Get CISM Certified

Official resource

Documentation · Free

Official certification requirements, experience requirements, application process, and certification steps.

View resource

Maintain CISM Certification

Official resource

Documentation · Free

Official CPE, maintenance-fee, ethics, audit, and certification-maintenance requirements.

View resource

Renewal

Validity period
3-year CPE reporting cycle with annual maintenance requirements
Renewal method
Maintain the CISM by earning and reporting at least 20 CPE hours each year and at least 120 CPE hours over each three-year reporting period, paying the annual certification maintenance fee, complying with the CPE audit if selected, and following ISACA's Code of Professional Ethics.
Notes
ISACA currently lists the annual CISM maintenance fee as $45 USD for members and $85 USD for non-members. Certification holders must remain current with annual and three-year CPE requirements and other maintenance obligations.

Recommended Before

Verify with official provider.

Recommended After

Verify with official provider.

Alternatives

Verify with official provider.

Specializations

Verify with official provider.

Explore certification categories

Browse focused certification guides by technology and career domain.