Cybersecurity

CISM (ISACA)

Certified Information Security Manager

By The Exam Atlas Editorial Team · Verified 2026-05-29

Quick facts

ProviderISACA
Exam codeCISM
Leveladvanced
FormatMultiple choice
Questions150 questions
Duration4 hours
Passing score450 / 800 (scaled)
Exam fee$575–$760 (member / non-member)
Validity3 years (CPE credits)
LanguagesEN, ES, JA, ZH

Overview

CISM (Certified Information Security Manager) is ISACA's management-focused security certification. Where CISSP is broad and technical-leaning, CISM is squarely about governance, risk and running a security programme, which makes it popular with managers and aspiring CISOs.

It requires five years of relevant management experience to certify, though you can pass the exam first and earn the experience within five years. It is frequently paired with, or chosen instead of, CISSP for leadership tracks.

Who it is for

Who it is not for

Exam structure

Information Security GovernanceEstablishing and maintaining a governance framework
Information Security Risk ManagementIdentifying and managing risk to acceptable levels
Information Security ProgramBuilding and running the security programme
Incident ManagementPlanning for and responding to incidents

How the exam is weighted

  • Information Security Governance 17%
  • Information Security Risk Management 20%
  • Information Security Program 33%
  • Incident Management 30%
Approximate official domain weighting — confirm the current split in the official exam objectives. Verified 2026-05-29.

Realistic study time

Bars show relative effort, not a guarantee. Your time depends on background and study method.

What it really costs

Exam feeUS$575 member / US$760 non-member
RetakeFull fee again
Study materialsUS$0-500 — ISACA review manual optional
ISACA maintenanceAnnual fee + CPE — member/non-member rates

Fees change and vary by region. Confirm the current amount on the official site before you register.

Is it worth it?

Worth it for people on a security-management track, where CISM is highly recognised and well paid. It is less suitable if you want to stay hands-on and technical, where CISSP or specialist certifications fit better.

What to do next

CISM suits the management track. Compare CISSP vs CISM if you are weighing technical breadth against governance focus.

FAQ

CISM or CISSP?
CISM is management and governance focused; CISSP is broader and more technical. Managers and aspiring CISOs often prefer CISM; technical leads often prefer CISSP. Some hold both.
Do I need experience for CISM?
Yes, five years in security management to certify, with some waivers. You can pass the exam first and accrue the experience within five years.
How do I maintain it?
Earn Continuing Professional Education (CPE) credits and pay ISACA's annual maintenance fee on a three-year cycle.

Related exams

Career paths featuring this exam

Free study resources

Sources