ISACA · information security management

CISM exam preparation

Practice for the Certified Information Security Manager (CISM) exam with adaptive questions, full-length mock exams, and a readiness score that tells you when you're actually ready to pass.

Before you register: You can sit the CISM exam before you have the experience — but passing it does not make you certified.

Certification requires five years of information security work experience, of which at least three must be in an information security management role across three or more of the four domains. Certain qualifications and general information security experience can waive up to two of the five years. You have five years from the date you pass to submit the application evidencing that experience; miss the window and the pass lapses and the exam must be retaken. Applicants also agree to ISACA’s Code of Professional Ethics and, once certified, to its continuing professional education requirements. Confirm the current rules with ISACA before you plan around them.

CISM exam at a glance

Issuer
ISACA
Questions
150 multiple-choice questions
Duration
4 hours (240 minutes)
Scoring
Scaled score 200–800
Pass mark
450 to pass
Format
Computer-based, multiple choice
Heads up: ISACA updates the CISM exam content outline on 3 November 2026. Exams sat before that date use the domain weights shown here; exams on or after it use a revised outline that adds Enterprise Architecture and Information Security Architecture as content areas. ISACA has not yet published the final domain-by-domain weights for the new outline, so treat any specific percentages you see quoted for it as unverified.

CISM exam domains

The CISM exam covers 4 domains, with the approximate weighting shown below:

What each CISM domain covers

Information Security Governance. How security is directed and held accountable rather than how it is operated: strategy aligned to business objectives, the governance framework, who owns which decision, and the legal, regulatory and contractual obligations the programme has to satisfy.

Information Security Risk Management. Identifying, analysing and responding to risk, and keeping that picture current. The exam repeatedly tests whether you treat risk as a business decision with an owner, rather than as a technical finding to be closed.

Information Security Program. Building and running the programme itself: resources, control design and implementation, awareness and training, third-party management, and the metrics that show whether any of it is working. This is the largest domain on the current outline.

Incident Management. Readiness before the event and coordination during it: classification and escalation, response and recovery plans, business continuity and disaster recovery, communication, and the post-incident review that feeds change back into the programme.

CISM exam facts

How CertPrepX helps you pass the CISM

Who the CISM is for

Information security managers, aspiring managers, and IT consultants who design and manage an enterprise information security program.

Start preparing for the CISM — free

Create a free account and start practicing today. Go Premium ($99/year) for full mock exams, analytics, and a Pass Guarantee.

Start free practice

CISM exam FAQ

How many questions are on the CISM exam?

The CISM exam has 150 multiple-choice questions with a 4-hour time limit.

What is the passing score for CISM?

CISM uses a scaled score from 200 to 800; you need 450 or higher to pass. The scale is a statistical conversion, not a percentage — 450 does not mean 56% correct.

What are the four CISM domains?

Information Security Governance, Information Security Risk Management, Information Security Program, and Incident Management.

Is the CISM exam changing in 2026?

Yes. ISACA updates the exam content outline on 3 November 2026, adding Enterprise Architecture and Information Security Architecture as content areas. If you are testing before that date you sit the current outline. ISACA has not yet published final domain weights for the new one.

Do I need five years of experience before I can sit the exam?

No. You can sit the exam at any time. The five years of information security experience — including three in a management role across three or more domains — is required to become certified, and you have five years after passing to evidence it.

What is the difference between CISM and CISA?

CISM is a management credential: strategy, risk, programme and incident response. CISA is an audit credential: evidence, controls testing and reporting. Most candidates pick based on whether they run security or assure it.

Sources

Exam details on this page come from ISACA’s own published materials and were last verified on 24 August 2026. ISACA can change exam policy at any time, so confirm current requirements with ISACA before you register.

Related reading

Other certifications