ISACA · CISM
Validates expertise in information security governance, risk management, program development, and incident management for experienced security professionals.
Practice Questions
1,196
≈ 7 practice exams
Duration
240 minutes
Passing Score
450/800
Difficulty
ProfessionalLast Updated
Jan 2026
CISM weights Information Security Program heaviest at 33 percent of the exam, followed by Incident Management at 30 percent, Information Security Risk Management at 20 percent, and Information Security Governance at 17 percent. This practice bank of 1,196 questions is built to match that split, so program-management and incident-response scenarios get proportionally more coverage than any single domain. Note that ISACA is updating the CISM exam content outline effective November 3, 2026 — if you're studying close to that date, verify you're working from the current outline.
On test day you face 150 questions in 4 hours, scored on a scale of 200 to 800, and you need 450 or higher to pass. Every question is multiple choice with one best answer among four options, often built around a management scenario rather than a factual recall prompt — CISM tests judgment about what a security manager should prioritize, not just what a control does.
Here's the part that catches people off guard: passing the exam alone does not make you CISM certified. ISACA also requires 5 or more years of information security management work experience within the CISM job practice areas, earned within the 10 years before you apply and spanning at least 3 of the 4 domains (experience waivers cover up to 2 years). You have 5 years after passing to submit your application. The exam costs $575 for ISACA members and $760 for non-members, plus a $50 application fee once you certify. Renewal requires 120 CPE hours over a 3-year cycle plus an annual maintenance fee ($45 members, $85 non-members). Start with the 30 free questions, then work through the full 1,196-question bank until your accuracy holds steady across all four domains.
The Certified Information Security Manager (CISM) is a globally recognized credential awarded by ISACA that validates expertise in managing, designing, and overseeing enterprise information security programs. First introduced in 2002, the certification has been earned by more than 107,000 professionals worldwide and was recognized as the 2025 Best Professional Certification Program. CISM is distinguished from technical certifications by its emphasis on governance, strategic alignment, and business outcomes — validating a practitioner's ability to bridge the gap between information security and organizational objectives.
The credential covers four core practice domains: Information Security Governance, Information Security Risk Management, Information Security Program, and Incident Management. Together, these domains assess a candidate's ability to establish security frameworks aligned with business goals, identify and manage information risk, develop and oversee a security program from inception through continuous improvement, and lead effective incident response and recovery operations. A forthcoming content outline update effective November 3, 2026 will reflect evolving job practice areas, with updated preparation materials available in September 2026.
CISM is designed for experienced information security professionals who have transitioned — or are seeking to transition — from purely technical roles into management and leadership positions. Ideal candidates include information security managers, IT directors, risk managers, security consultants, and compliance officers who are responsible for overseeing enterprise security strategy rather than executing day-to-day technical tasks.
Candidates typically have at least five years of professional information security work experience, with at least three years in security management roles across the CISM domains. The certification is particularly well-suited for professionals in financial services, healthcare, government, and technology sectors where security governance and risk oversight are critical organizational functions.
ISACA does not impose formal prerequisites for sitting the CISM exam — candidates may register and take the exam at any time. However, to apply for the full certification after passing, candidates must demonstrate a minimum of five years of professional information security management work experience within the CISM job practice domains. At least three of those five years must be in information security management. This experience must have been gained within the ten-year period preceding the certification application date, and candidates have five years from their exam passing date to submit their application.
While no specific prior certifications are required, a solid foundation in information security concepts, IT governance frameworks (such as COBIT or ISO/IEC 27001), risk management methodologies, and incident response principles is strongly recommended. Familiarity with regulatory and compliance environments relevant to one's industry will also be beneficial given the governance-heavy nature of the exam.
The CISM exam consists of 150 multiple-choice questions, all of which are scored. The exam is administered over a four-hour time limit. It is delivered as a computer-based test, available either at authorized PSI testing centers worldwide or via remote proctoring, giving candidates flexible delivery options. Registration is continuous — there are no fixed testing windows — and candidates can schedule an appointment as early as 48 hours after payment of the exam registration fee, up to 90 days in advance.
Scoring is reported on a scale of 200 to 800, with a passing score of 450. Questions are designed to assess practical, job-relevant judgment rather than rote memorization, drawing on real-world information security management scenarios. Exam fees are $575 USD for ISACA members and $760 USD for non-members, plus a $50 certification application fee upon passing.
CISM holders command some of the highest salaries in the information security field. U.S.-based professionals with the certification earn an average of approximately $140,000–$150,000 annually, with total compensation averaging above $165,000 when bonuses and benefits are included. Professionals who advance to CISO-level positions — a common trajectory for CISM holders — report average total compensation exceeding $300,000 at large enterprises. Most newly certified professionals report salary increases of $15,000 to $30,000 within their first year, and combining CISM with CISSP can command an additional 10–20% premium in many markets.
The certification opens doors to senior leadership roles including Information Security Manager, Security Director, Chief Information Security Officer, Risk Manager, and IT Compliance Manager across virtually every industry vertical. Government agencies and defense contractors frequently list CISM as a required or preferred credential for security management positions. With the U.S. Bureau of Labor Statistics projecting 33% job growth for information security analysts through 2033 and cybercrime costs projected at $10.5 trillion globally in 2025, demand for credentialed security managers remains strong. CISM's emphasis on business alignment and governance makes it particularly compelling to executive hiring managers who need security leaders who can communicate risk in terms of business impact.
5 sample questions with answers and explanations. The full bank has 1,196 questions, enough for 7 full-length practice exams.
Preview — answers shown1. A security manager implements NIST SP 800-37 Risk Management Framework for a federal information system. The system has been categorized as MODERATE impact. During the Select phase, the security team identifies 304 baseline controls from NIST SP 800-53. Before implementation, which RMF step must be completed to ensure controls are appropriate for the organization's environment? (Select one!)
Explanation
The NIST RMF seven-step process includes Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor. After selecting baseline controls in the Select phase, organizations must tailor them to their specific environment before implementation. Tailoring involves customizing controls based on organizational risk tolerance, operational requirements, and technical constraints. Implementation occurs after tailoring is complete. Assessment happens after implementation to verify control effectiveness. Authorization occurs only after successful assessment demonstrates controls are working as intended.
2. An organization implements role-based access control for enterprise applications supporting 5,000 users across multiple business units. The security manager must determine which access control model provides the MOST scalability and manageability for this environment. Which access control model is MOST appropriate? (Select one!)
Explanation
Role-Based Access Control is most appropriate for large enterprises with 5,000 users because it assigns permissions to roles based on job functions, dramatically reducing administrative overhead. Instead of managing 5,000 individual user permissions, administrators manage a much smaller number of roles. Discretionary Access Control with owner-based permissions becomes unmanageable at enterprise scale with inconsistent security. Mandatory Access Control is designed for government and military environments with formal classification levels, not typical business units. Attribute-Based Access Control provides the most flexibility and is ideal for complex environments and cloud, but adds complexity that may be unnecessary if RBAC meets requirements. RBAC provides the optimal balance of scalability, manageability, and security for large enterprises.
3. A security manager discovers that a critical business application hosted in the cloud processes customer financial data but the cloud service contract does not include specific security requirements or data protection clauses. The application has been operational for six months with no documented security assessment. What should the security manager do FIRST? (Select one!)
Explanation
Conducting a risk assessment is the first step to understand the actual security exposure, data classification levels, regulatory requirements, and potential business impact. This assessment provides the foundation for determining appropriate remediation actions and communicating risk to management. Immediately terminating the contract disrupts business operations without understanding impact or alternatives. Negotiating a contract addendum is premature without understanding current risk exposure and specific requirements needed. Transferring risk through insurance does not address the fundamental lack of security controls and should only be considered after assessment and mitigation efforts.
4. A financial institution experiences security incident where employee downloaded malware via phishing email, compromising workstation. The incident response team isolated the workstation within 15 minutes. Following NIST SP 800-61 incident response lifecycle, which activities should the team perform during the Containment, Eradication, and Recovery phase? (Select two!)
Multiple correct answersExplanation
Eradication involves removing malware and verifying elimination, while Recovery involves restoring systems from clean backups and validating functionality before returning to production. These activities directly address the phase objectives of eliminating threats and restoring normal operations. Analyzing email headers and malware samples occurs during Detection and Analysis phase to understand the incident. Documenting chain of custody is part of evidence handling throughout the response but not specific to Containment, Eradication, and Recovery. Lessons learned meetings occur during Post-Incident Activity phase after recovery is complete.
5. A security manager implements SABSA framework for enterprise security architecture. The conceptual layer defines security principles and mechanisms. The logical layer specifies information flows and security services. The physical layer identifies security products and technologies. Management requests visibility into business requirements and risk appetite. Which SABSA layer should the security manager present to management? (Select one!)
Explanation
The contextual layer represents the business view of security architecture, focusing on business requirements, goals, and risk appetite. This layer translates business needs into security requirements and is most appropriate for management presentations. The conceptual layer addresses architect-level security concepts and principles. The logical layer covers designer-level information flows and services. The component layer focuses on tradesman-level tools and technologies. Management needs the business-focused contextual view to understand how security aligns with organizational objectives.
150 questions in 4 hours, all multiple choice with one best answer among four options.
450 or higher on ISACA’s scaled score of 200 to 800.
$575 for ISACA members, $760 for non-members, plus a $50 application fee once you certify.
Information Security Program (33%), Incident Management (30%), Information Security Risk Management (20%), and Information Security Governance (17%).
Yes — passing the exam alone is not enough. You need 5 or more years of information security management experience within the CISM job practice areas, earned in the 10 years before applying and spanning at least 3 of the 4 domains. Experience waivers cover up to 2 years, and you have 5 years after passing to apply.
Yes. Renewal requires 120 CPE hours over a 3-year cycle plus an annual maintenance fee ($45 members, $85 non-members).
ISACA is updating the CISM exam content outline effective November 3, 2026, with updated prep materials on sale from September 2026. If you’re studying close to that date, confirm you’re using the current outline.
ISACA does not publish a pass rate. It tests management judgment — what a security manager should prioritize — more than technical control recall, which trips up candidates coming from a purely technical background.
Certified Data Privacy Solutions Engineer (CDPSE)
CDPSE · 749 questions
Certified in Risk and Information Systems Control (CRISC)
CRISC · 761 questions
Certified in the Governance of Enterprise IT (CGEIT)
CGEIT · 598 questions
Certified Information Systems Auditor (CISA)
CISA · 895 questions
Cloud Fundamentals Certificate
Cloud-Fund · 600 questions
COBIT Design & Implementation Certificate Program
COBIT-Design · 599 questions
$17.99
One-time access to this exam