Cybersecurity
CISM (ISACA)
Certified Information Security Manager
Free CISM practice questions 30 questions with full answer explanations. No sign-up. Start practice →Overview
CISM (Certified Information Security Manager) is ISACA's management-focused security certification. Where CISSP is broad and technical-leaning, CISM is squarely about governance, risk and running a security programme, which makes it popular with managers and aspiring CISOs.
It requires five years of relevant management experience to certify, though you can pass the exam first and earn the experience within five years. It is frequently paired with, or chosen instead of, CISSP for leadership tracks.
✓ Who it is for
- Security managers and team leads
- Professionals moving from technical roles into governance and risk
- Aspiring CISOs and security programme owners
- Risk, compliance or IT managers who own a security programme rather than operate the controls
- Consultants and vendors who advise clients on security strategy and governance
✕ Who it is not for
- Hands-on engineers who want technical depth - CISM is management-focused.
- Early-career people without security-management exposure (five years' experience is required to certify).
- Those who want a cheap, quick cert.
Exam structure
| Information Security Governance | Establishing and maintaining a governance framework |
|---|---|
| Information Security Risk Management | Identifying and managing risk to acceptable levels |
| Information Security Program | Building and running the security programme |
| Incident Management | Planning for and responding to incidents |
How the exam is weighted
- Information Security Governance 17%
- Information Security Risk Management 20%
- Information Security Program 33%
- Incident Management 30%
What each domain covers
- Information Security Governance
- Governance frameworks · Strategy aligned to business goals · Roles, responsibilities & metrics
- Information Security Risk Management
- Risk assessment & analysis · Risk treatment & response · Monitoring & reporting risk
- Information Security Program
- Program development & resources · Security controls & frameworks · Awareness & third-party management
- Incident Management
- Incident response planning · Detection, triage & containment · Recovery & post-incident review
Realistic study time
- Security manager (5+ yrs) 60-90 hours over 2-3 months
- Technical lead moving into management 100-150 hours
Bars show relative effort, not a guarantee. Your time depends on background and study method.
Turn this into a week-by-week schedule with the Study Plan Generator.
What it really costs
Fees change and vary by region. Confirm the current amount on the official site before you register.
Want your full out-of-pocket figure? Try the Cost Calculator.
Salary & career value
Indicative ranges for orientation only - not surveyed data, and not financial or career advice. Sources and date below.
CISM targets security management and pay reflects that. US holders in security-manager and governance roles commonly report roughly US$120k-175k, and the credential is frequently requested for management-track and CISO-pipeline roles.
Pass rate: Not published. ISACA does not disclose an official CISM pass rate, so figures quoted online are unofficial estimates rather than confirmed data. What is published is the scoring scale: results run from 200 to 800, and a scaled score of 450 is the passing mark.
Indicative annual pay (USD), each role's typical band on a shared scale.
Other markets (indicative)
| United Kingdom | ~£55k-85k |
|---|---|
| Canada | ~CA$100k-145k |
Jobs that often ask for it:
- Information Security Manager
- IT Risk Manager
- Governance / Compliance Lead
- Security Director
- CISO (with experience)
Is it worth it?
Worth it if you are on, or aiming at, a security-management track. CISM is highly recognised for governance, risk and programme-leadership roles, frequently requested in CISO-pipeline postings, and consistently among the better-paid security credentials. It is also a strong signal when you are moving from a technical role into management and want to prove you can think about security as a business function rather than a toolset. It is a poor fit if you want to stay hands-on and technical: the exam is about managing a programme, not configuring systems, so engineers are usually better served by CISSP or a specialist certification. Remember it takes five years of qualifying experience to fully certify, so it rewards people who already have, or are close to, that background.
Not sure this is the right exam for you? Compare your options with the Exam Finder.
Compare CISM with other exams
Independent, like-for-like comparisons to help you choose the right one.
Career paths featuring CISM
What to do next
CISM suits the management track. Compare CISSP vs CISM if you are weighing technical breadth against governance focus.
On exam day
Delivered at a centre or with remote proctoring via PSI/Pearson VUE; 150 multiple-choice questions in 4 hours. Government-issued ID required.
Keeping your certification
3-year cycle: earn and report 120 CPE hours (20 minimum per year) and pay ISACA's annual maintenance fee (member/non-member rates).
FAQ
- CISM or CISSP?
- CISM is management and governance focused; CISSP is broader and more technical. Managers and aspiring CISOs often prefer CISM; technical leads often prefer CISSP. Some hold both.
- Do I need experience for CISM?
- Yes, five years in security management to certify, with some waivers. You can pass the exam first and accrue the experience within five years.
- How do I maintain it?
- Earn Continuing Professional Education (CPE) credits and pay ISACA's annual maintenance fee on a three-year cycle.
- Is CISM worth it?
- For people on the security-management track it is high value and frequently requested for manager, governance and CISO-pipeline roles. It is less useful for hands-on technical specialists.
- Can I self-study for CISM?
- Yes. ISACA's exam content outline plus a review manual and practice questions are the usual route. The five years of management-level experience to certify is the real gate.
- What jobs can CISM help me get?
- Information security manager, IT risk and governance manager, security director, and it supports the move toward CISO. It is management-focused rather than technical.
- How much does CISM cost in total?
- The exam is US$575 for members or US$760 for non-members, plus optional review materials and ISACA's annual maintenance fee to keep it active.
Related exams
- CISSP (ISC2) - ISC2
- CompTIA Security+ (SY0-701) - CompTIA