Syllabus

CISM Domains Explained (The 4 CISM Domains)

By The Exam Atlas Editorial Team · Verified 2026-05-29

CISM is organised into four domains, all viewed from a management perspective. This is a plain-English summary with approximate weightings; ISACA’s official content is authoritative.

#DomainApprox. weight
1Information Security Governance~17%
2Information Security Risk Management~20%
3Information Security Program~33%
4Incident Management~30%

Domain 1 — Information Security Governance

Establishing and maintaining a governance framework: strategy aligned to business goals, roles and responsibilities, policies and standards, and metrics for leadership.

Domain 2 — Information Security Risk Management

Identifying and assessing information risk, selecting risk responses, and reporting risk in business terms, anchored in risk appetite and tolerance.

Domain 3 — Information Security Program

The largest domain: building, resourcing and running the security programme, selecting frameworks and controls, awareness, and managing third-party and operational security.

Domain 4 — Incident Management

Planning for and managing incidents: response plans and teams, detection and analysis, containment, eradication and recovery, continuity, and lessons learned.

FAQ

How many domains does CISM have?
Four: Information Security Governance, Information Security Risk Management, Information Security Program, and Incident Management.
Which CISM domain is largest?
Information Security Program is the largest, at roughly a third of the exam, followed closely by Incident Management.

Sources