ISACA CISM
A security-management credential centered on governance, risk management, security program development, security operations, and incident-management leadership.
Last verified: 2026-09-01
Overview
ISACA CISM (Certified Information Security Manager) is an advanced, vendor-neutral certification for professionals who manage, design, oversee, and assess enterprise information security programs. It emphasizes the management and governance side of cybersecurity rather than hands-on technical administration, with a strong focus on aligning security strategy with business goals, managing information security risk, building and operating security programs, and leading incident management activities.\n\nCISM is well suited to experienced security professionals moving into leadership, governance, risk, or program-management responsibilities. The credential is commonly associated with roles that require translating technical security concerns into business risk decisions, establishing security governance, directing security programs, and coordinating organizational response to security incidents.\n\nAs of September 2026, the active CISM exam uses four job-practice domains. ISACA has announced that an updated CISM exam content outline will take effect on November 3, 2026, so candidates planning to test after that date should review the new official outline before preparing.
- Recommended experience
- The CISM exam is open to anyone, but earning the certification requires at least five years of professional information security management experience within the CISM job-practice areas. ISACA states that candidates should have experience across at least three of the four CISM domains, and the required experience must generally fall within the 10 years preceding the certification application. Candidates have five years after passing the exam to apply for certification. Current ISACA policy allows qualifying substitutions or waivers for up to two years of the experience requirement.
- Estimated study time
- 100–160 hours
- Target job roles
- Information Security ManagerCybersecurity ManagerSecurity Program ManagerInformation Security OfficerGRC ManagerSecurity Risk ManagerSecurity Consultant
Exam Details
CISM Certification Exam
- Exam code
- CISM
- Number of exams
- 1
- Duration
- 240 minutes
- Question count
- 150 multiple-choice questions
- Delivery method
- Authorized PSI testing center or remotely proctored exam
- Price
- $575 USD for ISACA members; $760 USD for non-members
Skills and Domains
Information Security Governance
17%Covers enterprise governance and information security strategy, including organizational structures, legal and regulatory requirements, governance frameworks, strategic planning, resources, and alignment of security with business objectives.
Information Security Risk Management
20%Covers identifying, assessing, responding to, monitoring, and communicating information security risk, including emerging threats, vulnerabilities, control deficiencies, risk ownership, and treatment decisions.
Information Security Program
33%Covers development and management of an enterprise information security program, including resources, asset classification, policies, standards, controls, testing, awareness, third-party services, metrics, and reporting.
Incident Management
30%Covers incident-management readiness and operations, including response planning, business impact analysis, continuity and disaster recovery, incident classification, training, investigation, containment, recovery, communications, and post-incident improvement.
Study Resources
ISACA CISM Certification
Official resourceDocumentation · Free
Official CISM certification overview, registration information, pricing, preparation links, and certification process.
View resourceCISM Exam Content Outline
Official resourceOfficial Guide · Free
Official ISACA CISM exam domains, weights, job-practice areas, and exam-content guidance.
View resourceGet CISM Certified
Official resourceDocumentation · Free
Official certification requirements, experience requirements, application process, and certification steps.
View resourceMaintain CISM Certification
Official resourceDocumentation · Free
Official CPE, maintenance-fee, ethics, audit, and certification-maintenance requirements.
View resourceRenewal
- Validity period
- 3-year CPE reporting cycle with annual maintenance requirements
- Renewal method
- Maintain the CISM by earning and reporting at least 20 CPE hours each year and at least 120 CPE hours over each three-year reporting period, paying the annual certification maintenance fee, complying with the CPE audit if selected, and following ISACA's Code of Professional Ethics.
- Notes
- ISACA currently lists the annual CISM maintenance fee as $45 USD for members and $85 USD for non-members. Certification holders must remain current with annual and three-year CPE requirements and other maintenance obligations.
Related Certifications
Recommended Before
Verify with official provider.
Recommended After
Verify with official provider.
Alternatives
Verify with official provider.
Specializations
Verify with official provider.
Keep exploring on ThirdBadge
Connect this certification to its broader technology area, career roadmaps, training, and study resources.
Explore certification categories
Browse focused certification guides by technology and career domain.