Cybersecurity

CISM (ISACA)

advanced

Certified Information Security Manager

By The Exam Atlas Editorial Team · Verified 2026-05-29

Free CISM practice questions 30 questions with full answer explanations. No sign-up. Start practice →

Overview

CISM (Certified Information Security Manager) is ISACA's management-focused security certification. Where CISSP is broad and technical-leaning, CISM is squarely about governance, risk and running a security programme, which makes it popular with managers and aspiring CISOs.

It requires five years of relevant management experience to certify, though you can pass the exam first and earn the experience within five years. It is frequently paired with, or chosen instead of, CISSP for leadership tracks.

✓ Who it is for

  • Security managers and team leads
  • Professionals moving from technical roles into governance and risk
  • Aspiring CISOs and security programme owners
  • Risk, compliance or IT managers who own a security programme rather than operate the controls
  • Consultants and vendors who advise clients on security strategy and governance

✕ Who it is not for

  • Hands-on engineers who want technical depth - CISM is management-focused.
  • Early-career people without security-management exposure (five years' experience is required to certify).
  • Those who want a cheap, quick cert.

Exam structure

Information Security GovernanceEstablishing and maintaining a governance framework
Information Security Risk ManagementIdentifying and managing risk to acceptable levels
Information Security ProgramBuilding and running the security programme
Incident ManagementPlanning for and responding to incidents

How the exam is weighted

  • Information Security Governance 17%
  • Information Security Risk Management 20%
  • Information Security Program 33%
  • Incident Management 30%
Approximate official domain weighting - confirm the current split in the official exam objectives. Verified 2026-05-29.

What each domain covers

Information Security Governance
Governance frameworks · Strategy aligned to business goals · Roles, responsibilities & metrics
Information Security Risk Management
Risk assessment & analysis · Risk treatment & response · Monitoring & reporting risk
Information Security Program
Program development & resources · Security controls & frameworks · Awareness & third-party management
Incident Management
Incident response planning · Detection, triage & containment · Recovery & post-incident review

Realistic study time

  • Security manager (5+ yrs) 60-90 hours over 2-3 months
  • Technical lead moving into management 100-150 hours

Bars show relative effort, not a guarantee. Your time depends on background and study method.

Turn this into a week-by-week schedule with the Study Plan Generator.

What it really costs

Exam fee US$575 member / US$760 non-member
Retake Full fee again
Study materials US$0-500 ISACA review manual optional
ISACA maintenance Annual fee + CPE member/non-member rates

Fees change and vary by region. Confirm the current amount on the official site before you register.

Want your full out-of-pocket figure? Try the Cost Calculator.

Salary & career value

Indicative ranges for orientation only - not surveyed data, and not financial or career advice. Sources and date below.

CISM targets security management and pay reflects that. US holders in security-manager and governance roles commonly report roughly US$120k-175k, and the credential is frequently requested for management-track and CISO-pipeline roles.

Pass rate: Not published. ISACA does not disclose an official CISM pass rate, so figures quoted online are unofficial estimates rather than confirmed data. What is published is the scoring scale: results run from 200 to 800, and a scaled score of 450 is the passing mark.

IT Risk / Governance Analyst ~$95k-130k
IT Audit Manager ~$110k-150k
Information Security Manager ~$120k-160k
Security Director ~$150k-180k
CISO (with experience) ~$180k-250k+

Indicative annual pay (USD), each role's typical band on a shared scale.

Other markets (indicative)

United Kingdom~£55k-85k
Canada~CA$100k-145k

Jobs that often ask for it:

  • Information Security Manager
  • IT Risk Manager
  • Governance / Compliance Lead
  • Security Director
  • CISO (with experience)

Is it worth it?

Worth it if you are on, or aiming at, a security-management track. CISM is highly recognised for governance, risk and programme-leadership roles, frequently requested in CISO-pipeline postings, and consistently among the better-paid security credentials. It is also a strong signal when you are moving from a technical role into management and want to prove you can think about security as a business function rather than a toolset. It is a poor fit if you want to stay hands-on and technical: the exam is about managing a programme, not configuring systems, so engineers are usually better served by CISSP or a specialist certification. Remember it takes five years of qualifying experience to fully certify, so it rewards people who already have, or are close to, that background.

Not sure this is the right exam for you? Compare your options with the Exam Finder.

Our specialty · side by side

Compare CISM with other exams

Independent, like-for-like comparisons to help you choose the right one.

Where it leads

Career paths featuring CISM

What to do next

CISM suits the management track. Compare CISSP vs CISM if you are weighing technical breadth against governance focus.

On exam day

Delivered at a centre or with remote proctoring via PSI/Pearson VUE; 150 multiple-choice questions in 4 hours. Government-issued ID required.

Keeping your certification

3-year cycle: earn and report 120 CPE hours (20 minimum per year) and pay ISACA's annual maintenance fee (member/non-member rates).

FAQ

CISM or CISSP?
CISM is management and governance focused; CISSP is broader and more technical. Managers and aspiring CISOs often prefer CISM; technical leads often prefer CISSP. Some hold both.
Do I need experience for CISM?
Yes, five years in security management to certify, with some waivers. You can pass the exam first and accrue the experience within five years.
How do I maintain it?
Earn Continuing Professional Education (CPE) credits and pay ISACA's annual maintenance fee on a three-year cycle.
Is CISM worth it?
For people on the security-management track it is high value and frequently requested for manager, governance and CISO-pipeline roles. It is less useful for hands-on technical specialists.
Can I self-study for CISM?
Yes. ISACA's exam content outline plus a review manual and practice questions are the usual route. The five years of management-level experience to certify is the real gate.
What jobs can CISM help me get?
Information security manager, IT risk and governance manager, security director, and it supports the move toward CISO. It is management-focused rather than technical.
How much does CISM cost in total?
The exam is US$575 for members or US$760 for non-members, plus optional review materials and ISACA's annual maintenance fee to keep it active.

Related exams

Free study resources

Sources