CISM exam preparation
Practice for the Certified Information Security Manager (CISM) exam with adaptive questions, full-length mock exams, and a readiness score that tells you when you're actually ready to pass.
Before you register: You can sit the CISM exam before you have the experience — but passing it does not make you certified.
Certification requires five years of information security work experience, of which at least three must be in an information security management role across three or more of the four domains. Certain qualifications and general information security experience can waive up to two of the five years. You have five years from the date you pass to submit the application evidencing that experience; miss the window and the pass lapses and the exam must be retaken. Applicants also agree to ISACA’s Code of Professional Ethics and, once certified, to its continuing professional education requirements. Confirm the current rules with ISACA before you plan around them.
CISM exam at a glance
CISM exam domains
The CISM exam covers 4 domains, with the approximate weighting shown below:
- Information Security Governance17%
- Information Security Risk Management20%
- Information Security Program33%
- Incident Management30%
What each CISM domain covers
Information Security Governance. How security is directed and held accountable rather than how it is operated: strategy aligned to business objectives, the governance framework, who owns which decision, and the legal, regulatory and contractual obligations the programme has to satisfy.
Information Security Risk Management. Identifying, analysing and responding to risk, and keeping that picture current. The exam repeatedly tests whether you treat risk as a business decision with an owner, rather than as a technical finding to be closed.
Information Security Program. Building and running the programme itself: resources, control design and implementation, awareness and training, third-party management, and the metrics that show whether any of it is working. This is the largest domain on the current outline.
Incident Management. Readiness before the event and coordination during it: classification and escalation, response and recovery plans, business continuity and disaster recovery, communication, and the post-incident review that feeds change back into the programme.
CISM exam facts
- Questions: 150 multiple-choice questions.
- Duration: 4 hours (240 minutes).
- Answer options: Four per question: one correct response and three distractors.
- Scoring: A scaled score from 200 to 800. The scale is a statistical conversion of how many questions you answered correctly, not a percentage, so there is no fixed number of correct answers that guarantees a pass.
- Passing score: 450.
- Qualifier style: Many stems turn on a single word — BEST, MOST, FIRST, LEAST or EXCEPT. Several options are usually defensible; the qualifier decides which one the exam wants.
- Outline change: A revised exam content outline takes effect on 3 November 2026.
- Application window: Five years from passing to evidence the experience and apply.
How CertPrepX helps you pass the CISM
- Adaptive practice that focuses on your weakest CISM domains.
- Full-length, timed mock exams that mirror the real CISM format and scoring.
- A readiness score per domain, so you know when you're ready to sit the exam.
- Weak-area review and spaced repetition to lock in what you miss.
- A personalized study plan built around your target CISM exam date.
Who the CISM is for
Information security managers, aspiring managers, and IT consultants who design and manage an enterprise information security program.
Start preparing for the CISM — free
Create a free account and start practicing today. Go Premium ($99/year) for full mock exams, analytics, and a Pass Guarantee.
Start free practiceCISM exam FAQ
How many questions are on the CISM exam?
The CISM exam has 150 multiple-choice questions with a 4-hour time limit.
What is the passing score for CISM?
CISM uses a scaled score from 200 to 800; you need 450 or higher to pass. The scale is a statistical conversion, not a percentage — 450 does not mean 56% correct.
What are the four CISM domains?
Information Security Governance, Information Security Risk Management, Information Security Program, and Incident Management.
Is the CISM exam changing in 2026?
Yes. ISACA updates the exam content outline on 3 November 2026, adding Enterprise Architecture and Information Security Architecture as content areas. If you are testing before that date you sit the current outline. ISACA has not yet published final domain weights for the new one.
Do I need five years of experience before I can sit the exam?
No. You can sit the exam at any time. The five years of information security experience — including three in a management role across three or more domains — is required to become certified, and you have five years after passing to evidence it.
What is the difference between CISM and CISA?
CISM is a management credential: strategy, risk, programme and incident response. CISA is an audit credential: evidence, controls testing and reporting. Most candidates pick based on whether they run security or assure it.
Sources
Exam details on this page come from ISACA’s own published materials and were last verified on 24 August 2026. ISACA can change exam policy at any time, so confirm current requirements with ISACA before you register.