ISACA · CISM
Validates expertise in information security governance, risk management, program development, and incident management for experienced security professionals.
Practice Questions
1,196
≈ 7 practice exams
Duration
240 minutes
Passing Score
450/800
Difficulty
ProfessionalLast Updated
Oct 2026
CISM tests security leadership through Information Security Governance, Information Security Risk Management, Information Security Program, and Incident Management. The current outline weights those domains at 17%, 20%, 33%, and 30%. A revised outline takes effect November 3, 2026, shifting the weights to 18%, 20%, 33%, and 29% and explicitly expanding enterprise and security architecture coverage.
The exam contains 150 multiple-choice questions in four hours. ISACA uses a 200-800 scale with 450 required to pass; registration costs $575 for members or $760 for nonmembers. Anyone may take the test, but certification separately requires five years of information-security experience, including three years of management experience across at least three CISM domains.
Use these 884 questions to practise decisions from a security manager's perspective: align with business objectives, establish accountability and risk treatment, build a measurable program, and direct incident readiness and response. Check your appointment date before studying - exams on or after November 3 use the revised outline, while earlier appointments use the current one.
CISM validates the management of enterprise information security through governance, risk management, program development and management, and incident management. It focuses on aligning security decisions with business objectives and directing an effective program rather than administering individual controls.
The current weights are 17%, 20%, 33%, and 30%. A revised outline takes effect November 3, 2026, changing those weights to 18%, 20%, 33%, and 29% and expanding enterprise and security architecture coverage.
CISM is designed for experienced information security professionals who have transitioned — or are seeking to transition — from purely technical roles into management and leadership positions. Ideal candidates include information security managers, IT directors, risk managers, security consultants, and compliance officers who are responsible for overseeing enterprise security strategy rather than executing day-to-day technical tasks.
Candidates typically have at least five years of professional information security work experience, with at least three years in security management roles across the CISM domains. The certification is particularly well-suited for professionals in financial services, healthcare, government, and technology sectors where security governance and risk oversight are critical organizational functions.
ISACA does not impose formal prerequisites for sitting the CISM exam — candidates may register and take the exam at any time. However, to apply for the full certification after passing, candidates must demonstrate a minimum of five years of professional information security management work experience within the CISM job practice domains. At least three of those five years must be in information security management. This experience must have been gained within the ten-year period preceding the certification application date, and candidates have five years from their exam passing date to submit their application.
While no specific prior certifications are required, a solid foundation in information security concepts, IT governance frameworks (such as COBIT or ISO/IEC 27001), risk management methodologies, and incident response principles is strongly recommended. Familiarity with regulatory and compliance environments relevant to one's industry will also be beneficial given the governance-heavy nature of the exam.
CISM has 150 multiple-choice questions and allows four hours. ISACA scores the exam from 200 to 800 and requires 450 to pass. Registration is continuous through PSI, and the listed fee is $575 for members or $760 for nonmembers.
The outline depends on the appointment date: tests before November 3, 2026 use the current weights, while tests on or after that date use the revised outline. Candidates should use the matching official preparation material.
CISM demonstrates the ability to govern and manage an information-security program, communicate risk in business terms, allocate resources, establish measures, and lead incident readiness and response. It is relevant to security manager, director, program lead, risk manager, and governance roles.
Certification requires qualifying experience beyond the exam and ongoing maintenance through ISACA's continuing-professional-education, ethics, and annual-fee requirements.
5 sample questions with answers and explanations. The full bank has 1,196 questions, enough for 7 full-length practice exams.
Preview — answers shown1. A security manager reviews the organization's security controls after a malware infection. Antivirus software detected and quarantined the malware before it caused damage. Which type of security control did the antivirus software provide? (Select one!)
Explanation
Detective controls identify and detect malicious activities when they occur. Antivirus software that detects and reports malware after it enters the system functions as a detective control. The detection and alerting capability is the primary function even though quarantine follows detection. Preventive controls stop incidents before they occur, such as application whitelisting that blocks malware execution entirely. Corrective controls remediate after detection, such as restoring from backup after infection. Compensating controls provide alternative protection when primary controls cannot be implemented. Detective controls are essential components of defense-in-depth strategies, working alongside preventive and corrective controls.
2. A security manager evaluates the policy hierarchy for the organization. The security team proposes creating a document that specifies AES-256 as the mandatory encryption algorithm for data at rest. Under which category should this document be classified? (Select one!)
Explanation
Security standards define specific mandatory technical requirements and specify HOW security policies will be implemented technically. The requirement for AES-256 encryption is a specific technical mandate that implements a higher-level policy about data protection. Security policies provide high-level management intent defining WHAT must be done. Security procedures provide step-by-step instructions for implementing standards. Security guidelines offer non-mandatory recommendations and best practices. Standards are stable but updated periodically to reflect technology changes, making them appropriate for specifying cryptographic requirements.
3. An organization conducts quantitative risk assessment for its e-commerce platform. The web server has an asset value of $500,000. Hard drive failure occurs once every four years with 40% data loss expected. What is the Annualized Loss Expectancy (ALE) for this risk scenario? (Select one!)
Explanation
ALE is calculated using the formula: ALE = SLE × ARO. First calculate Single Loss Expectancy: SLE = Asset Value × Exposure Factor = $500,000 × 0.40 = $200,000. Then calculate Annualized Rate of Occurrence: ARO = 1 failure every 4 years = 0.25 per year. Finally: ALE = $200,000 × 0.25 = $50,000 per year. This represents the expected annual loss from hard drive failures and guides cost-benefit analysis for implementing preventive controls like RAID or enhanced backup solutions.
4. A security manager reviews vendor management procedures. The organization contracts with a cloud service provider that uses multiple subcontractors for data processing and storage. Which risk management concept addresses the security risks introduced by the vendor's subcontractors? (Select one!)
Explanation
Fourth-party risk addresses security risks from vendor's critical subcontractors and downstream dependencies that the organization does not directly control or contract with. The primary vendor is the third party, and their subcontractors are fourth parties introducing extended supply chain risk. Organizations have limited visibility and control over fourth-party relationships, creating hidden risk exposures. Second-party risk is not standard risk terminology in vendor management contexts. Third-party risk refers to risks from direct vendor relationships where the organization has contractual agreements and some control through contract terms, SLAs, and security requirements. Inherent risk is the risk level before controls are applied, used in risk assessment contexts rather than vendor relationship terminology. Security managers must implement Third-Party Risk Management (TPRM) lifecycle including vendor identification, risk assessment, due diligence, contracting with security requirements, onboarding, ongoing monitoring, and offboarding. Contracts should require vendors to disclose subcontractor relationships, extend security requirements to fourth parties, and provide right to audit capabilities. Cloud service providers particularly introduce fourth-party risk through infrastructure providers, data center operators, and service subcontractors. Supply chain attacks increasingly target fourth-party weaknesses to compromise ultimate targets.
5. A security manager designs disaster recovery capabilities for mission-critical systems with Recovery Time Objective of 2 hours and Recovery Point Objective of 15 minutes. Which recovery site type is MOST appropriate? (Select one!)
Explanation
A hot site with real-time replication is required to meet a 2-hour RTO and 15-minute RPO. Hot sites are fully operational facilities with installed equipment and real-time data synchronization that enable recovery within minutes to hours. Real-time replication ensures data is current within 15 minutes, meeting the aggressive RPO. Cold sites are empty facilities requiring days to weeks for equipment installation and data restoration from backups, making them unsuitable for 2-hour RTO. Daily backup tapes cannot meet 15-minute RPO requirements. Warm sites have hardware installed but require hours to days for data restoration from periodic backups, which cannot meet the 15-minute RPO. Mobile sites are self-contained trailers with variable activation times and rely on transported backups. Weekly backups create potential 7-day data loss far exceeding the 15-minute RPO requirement. Hot sites cost significantly more than warm or cold sites but are necessary when business criticality demands rapid recovery. RTO determines technology investment level while RPO determines data synchronization frequency. Security managers must balance business requirements against recovery costs when recommending site types.
CISM has 150 multiple-choice questions and allows four hours.
ISACA reports scores from 200 to 800 and requires 450 to pass.
The revised outline takes effect November 3, 2026. Appointments before that date use the current outline.
Governance changes from 17% to 18%, Risk remains 20%, Program remains 33%, and Incident Management changes from 30% to 29%.
Certification requires five years of information-security experience, including three years managing security across at least three CISM domains, subject to ISACA's current rules.
CISM is for governing and managing a security program; CISA is for auditing systems, controls, and governance independently.
Certified Information Systems Auditor (CISA)
CISA · 895 questions
Certified in Risk and Information Systems Control (CRISC)
CRISC · 761 questions
Certified Data Privacy Solutions Engineer (CDPSE)
CDPSE · 749 questions
Certified in the Governance of Enterprise IT (CGEIT)
CGEIT · 598 questions
Cloud Fundamentals Certificate
Cloud-Fund · 600 questions
COBIT Design & Implementation Certificate Program
COBIT-Design · 599 questions
$17.99
One-time access to this exam