Other Certifications · ISACA · CISM

CISM — Certified Information Security Manager

Every certification this course has covered so far tests whether you can build, scan, gate, or harden something with your own hands. The CISM tests a different question entirely: can you run the program that all of that hands-on work sits inside — set the strategy, own the risk register, fund and staff the function, and lead the room when an incident is actually happening? It's ISACA's flagship credential for exactly that pivot, from doing security work to managing a security program, and it pairs directly with this course's own compliance & governance lesson. Below: what the exam actually tests, its four weighted job-practice domains, the experience requirement that makes it unlike every hands-on exam on this site, and who should — and shouldn't — reach for it next.

☺ Explain it like I'm 10

Some badges prove you can fix a leaking pipe yourself — wrench in hand, done in ten minutes. This one proves something else: that you could run the whole building's plumbing department. Not just "can you fix a pipe," but "do you know how many pipes there are, which ones are close to bursting, who gets called at 2am when one actually does, and can you explain to the people who pay for the building why fixing pipes before they burst is worth the money."

🐿️🐼Your hosts for this topic: Nutty the Squirrel & Master Panda — Nutty already keeps the compliance evidence this exam is built to reason about, over at compliance & governance; Master Panda is here for the part that isn't a checklist at all — the patience to build a funded, staffed security program one decision at a time, over at security culture & champions.

What the CISM actually is, and the pivot it tests

☺ Like you're 10: It's not a test about knowing how to lock a door. It's a test about deciding which doors get locks, who holds the keys, and how you'd defend that budget line to your boss.

The Certified Information Security Manager is run by ISACA — a global nonprofit (founded in 1969 as the EDP Auditors Association) that also administers CISA (information systems auditing), CRISC (IT risk), and CGEIT (enterprise IT governance). CISM has existed since the early 2000s and is deliberately not a technical exam: it doesn't ask what a NetworkPolicy does or how cosign verify works. It asks whether you can govern, resource, and run the security function that decides those tools get used in the first place — align a security strategy with business objectives, manage risk at the enterprise level, build and operate a security program, and lead an organization through an incident rather than just execute a runbook.

That makes it structurally different from the other credential this course already profiles in depth. The CKS hands you a live cluster and grades what you actually did to it; CISM hands you a case and grades whether you'd make the right call as the person accountable for the whole program — with no cluster, no terminal, and no partial credit for correct syntax.

◆ Key idea

CISM doesn't compete with the technical certifications on this site — it sits a level above them. A CKS or a CSSLP proves you can execute a control. CISM proves you can decide which controls the organization should be funding, staffed by whom, and measured how — the exact discipline behind this course's own compliance & governance lesson, formalized into a credential.

Format, cost, and the experience requirement

☺ Like you're 10: Multiple choice, no terminal — but you can't just study your way past the biggest requirement. This one wants years of the job first.

CISM is a computer-based, multiple-choice exam delivered through Pearson VUE — either at a physical test center or via online remote proctoring, depending on region. There's no live environment and no performance-based component, which puts it in a different assessment family from the CKS or the CDP covered elsewhere on this site, and closer in spirit to the AWS Security – Specialty exam: knowledge and judgment tested through scenario-style questions rather than hands-on tasks.

ItemWhat is generally published
FormatComputer-based, multiple-choice — no performance-based or hands-on component
Question count150 questions
Duration4 hours
ScoringScaled score from 200–800; a scaled score of 450 is generally treated as passing
Experience requirementA minimum of 5 years of information security work experience, including several years specifically in security management across a spread of the exam's job-practice domains — ISACA publishes the exact minimums and the domain spread
Experience substitutionsISACA publishes one- and two-year waivers for other certifications (CISA, CISSP), a security-related degree, or general information-security experience, up to a published cap — check the current substitution table, it has been revised more than once
Sit-before-you-qualifyYou can sit and pass the exam before meeting the experience requirement — but ISACA will not issue the certification until you submit verified evidence of the required experience, generally within 5 years of your exam pass date
Ethics & CPECertified members must adhere to ISACA's Code of Professional Ethics and complete ongoing Continuing Professional Education — historically around 120 CPE hours over a 3-year cycle, with an annual minimum, plus an annual maintenance fee
PriceTiered by ISACA membership — historically noticeably cheaper for members than non-members, with regional and early-registration pricing common; budget for a few hundred US dollars either way

That "sit-before-you-qualify" row is the detail worth sitting with, because it's the opposite shape from the CKS's gate. CKS won't even let you register without an active CKA already in hand — a hard block before you can attempt anything. CISM lets you take and pass the exam on pure knowledge, then makes you prove the years of management experience afterward before the certification itself is issued. Passing young and management-inexperienced gets you a passed exam, not a certification — those are not the same thing here.

⚠ Verify this before you book

Question count, passing score, price, the exact experience-substitution table, and CPE requirements all change. Nothing on this page is authoritative — this site is independent and unofficial. Confirm current details on ISACA's own official CISM page before you register, and read the current CISM Exam Candidate Guide for the full experience-verification process — it's a genuinely multi-step process, not a checkbox on a form.

↗ ISACA official CISM page

The four job-practice domains, weighted

☺ Like you're 10: Four topics, and they're not equal — but group them differently and a clean 50/50 split falls out.

These are the four domains from ISACA's most recent published CISM job practice analysis. ISACA periodically re-surveys practicing security managers and revises both the domain names and their weights, so treat these as directionally correct and verify the current split before building a study plan around exact percentages.

🏛️Information Security Governance
17%
⚖️Information Security Risk Management
20%
🗂️Information Security Program
33%
🚨Information Security Incident Management
30%

Listed in that order, Program is the single largest domain at a third of the exam — unsurprising, since "run the program" is the job title's whole premise. But regroup the same four domains by function rather than curriculum order, and a cleaner, genuinely useful pattern falls out.

50% / 50% — build the program, then prove it survives an actual incident Build & govern the program — 50% Governance 17% Program 33% Assess risk & respond — 50% Risk Mgmt 20% Incident Mgmt 30% Nutty's territory — compliance & governance Foxy's territory — incident response & forensics Curriculum order interleaves these four; grouped this way, exactly half the exam is design work and half is crisis-response leadership.

Domain by domain: what's actually tested, and how it connects to this course

☺ Like you're 10: Here's the real substance behind each of those four percentages, and which lesson on this site covers the ground-level version of the same idea.

Information Security Governance — 17%

This domain is about establishing and maintaining a governance framework that puts security decisions on the same footing as any other business decision: aligning security strategy with organizational strategy and risk appetite, securing genuine senior-leadership commitment rather than a signature on a policy nobody reads, defining who is accountable for what across the organization, and building the reporting lines that keep executives and the board actually informed rather than surprised.

This is the formal version of an argument this course already makes informally. What is DevSecOps? frames CALMS' "Culture" and "Sharing" pillars as security earning a seat at the table through automation and shared dashboards; the Governance domain asks you to earn and defend that seat explicitly, in front of people who control budget and headcount rather than a CI pipeline.

Information Security Risk Management — 20%

Establishing and maintaining a risk management process integrated with the enterprise's own risk management, then identifying, analyzing, evaluating, and treating risk on an ongoing basis — not once at a design review, but as a standing program with a maintained risk register, defined risk appetite and tolerance thresholds, and regular reporting to stakeholders who aren't security specialists.

The tactical, per-feature version of this same discipline is already covered in threat modeling — walking through STRIDE against one feature's data flow diagram. CISM asks you to run that same instinct as a continuous, enterprise-wide program instead of a one-time design exercise: dozens of open risks tracked simultaneously, each with an owner, a treatment decision, and a review date.

# A risk-register entry — the concrete artifact the Governance and Risk
# Management domains expect a real program to produce, not just discuss
- risk_id: RISK-2026-014
  title: "Unsigned container images can reach production"
  domain: "Information Security Risk Management"
  identified: 2026-06-02
  likelihood: Medium
  impact: High
  inherent_risk: High
  treatment: Mitigate
  control: "cosign verification enforced at admission via a Kyverno policy"
  owner: "Platform Security Lead"
  residual_risk: Low
  next_review: 2026-11-01

Information Security Program — 33%

The largest domain, and the closest thing CISM has to a job description: establish and maintain the security program itself, aligned to the governance framework the first domain built. That covers security architecture across people, process, and technology; documentation — policies, standards, procedures, guidelines; the program's own budget, staffing, and vendor and third-party management; ongoing security awareness and training; and defining and monitoring the metrics that prove the program is actually working, not just present.

Nearly every other lesson in this course is a piece of what this domain expects a manager to fund, staff, and measure as a coherent whole: SAST, DAST & SCA and security in CI/CD are controls this domain has to budget tooling and headcount for; container & supply-chain security is architecture this domain has to standardize across every team, not just the one that built it first; and the tooling landscape is the vendor-management reality behind "which scanner, which SBOM tool, which secrets manager, and why."

🐿️ Nutty's exercise · 30 min

No cluster required for this one. Pick one control already covered elsewhere in this course — say, mandatory image signing before deploy — and write the one-page business case a CISM-style program manager would actually have to produce: the risk it mitigates, the cost to implement and maintain (tooling, engineering time, an on-call rotation for signing-key rotation), the metric that would prove it's working six months in, and who signs off on the budget. If you can't fill in all four honestly, that's the real gap this domain tests — not whether you know what cosign does.

Information Security Incident Management — 30%

Establishing and maintaining an incident response plan and the capability behind it: classification and categorization of incidents by severity, documented processes for investigation, escalation, and communication — including legal and regulatory breach-notification obligations, which have their own deadlines independent of how fast the technical fix takes — integration with business continuity and disaster recovery planning, and periodically testing the plan and folding lessons learned back into it rather than filing the after-action report and moving on.

This is the program-level version of incident response & forensics — that lesson covers running the actual investigation and reconstructing what happened; this domain covers whether the plan, the escalation chain, the legal notification clock, and the post-incident review process were in place and rehearsed before the incident, so the response isn't being improvised for the first time under pressure. The Capital One breach and the SolarWinds case study are worth rereading with this domain's lens specifically: not "what was the technical root cause" but "what did the response plan, the notification timeline, and the post-incident program changes actually look like."

CISM versus CISSP versus CSSLP — three credentials, three different altitudes

☺ Like you're 10: All three have "security" in the name. One asks if you can run the program, one asks if you can speak to the whole field, and one asks if you can build genuinely secure software.

These three come up together constantly because career paths cross all three, but they test different things and shouldn't be treated as interchangeable or strictly ordered.

CISMCISSPCSSLP
Question it answersCan you govern and run a security program?Can you speak to the whole security domain, technical and managerial?Can you build software that's secure across its whole lifecycle?
Issuing bodyISACA(ISC)²(ISC)²
Scope4 management-focused domains8 broad domains spanning technical and managerial security8 domains, all anchored to the secure SDLC specifically
Format150 questions, multiple choice, 4 hoursAdaptive or linear multiple choice, roughly 3–4 hoursMultiple choice, roughly 3 hours
Experience gate5 years, verified after the exam if needed5 years across CISSP's domains (associate status available without it)4 years, or 3 with a relevant degree
Best fitSecurity managers, AppSec/program leads, CISO-trackBroad security leadership or architecture roles spanning build and governEngineers and architects moving into AppSec leadership while staying close to code

For a DevSecOps engineer specifically, the practical distinction is which half of the job you're moving toward. CSSLP stays closest to what this course's secure SDLC lesson already covers — it's the deepest of the three on secure coding and lifecycle practice, and the natural next step if you want to lead AppSec while remaining hands-on with how software gets built. CISSP is the broadest of the three, spanning both build and govern, and fits someone aiming at a general security-leadership title that isn't narrowly scoped to program management. CISM is the narrowest and most explicitly management-focused of the three — no architecture domain, no cryptography domain, just governance, risk, program, and incident management, tested in depth rather than breadth.

Who should consider it, and where CISM sits among the credentials here

☺ Like you're 10: This test rewards someone who's already been the one explaining a security decision to a room that doesn't know what a container is.

CISM fits a specific and fairly narrow moment: a DevSecOps engineer or lead who is being asked — or wants to be asked — to own budget, hiring, vendor selection, board or executive reporting, or a security program as a whole, rather than the pipeline gates and scanners that feed into it. It's also a natural pairing for anyone who's already built technical credibility through CKS, an offensive-security credential, or hands-on years in the role, and now wants a credential that specifically validates the management half of a CISO-track career rather than repeating the technical case they've already made.

Skip it, or at least delay it, if any of these fit. You're still purely an individual contributor and want to stay one — CISM tests almost nothing about hands-on execution, so the return on studying governance frameworks is low if your near-term goal is deeper technical mastery; CKS or CSSLP will track your actual work far more closely. You don't yet have several years of security-adjacent experience — you can technically sit and pass the exam early, but the certification itself won't issue until you can verify the experience, so there's little urgency in cramming for it years ahead of that milestone. Your organization has no separate security-management track to grow into — a broader, less management-specific credential like CISSP may open more doors than a narrowly management-focused one. And if the itch is specifically "I want to write more secure code and lead that effort," CSSLP is the closer match, not CISM.

Within ISACA's own family, CISM sits alongside CISA (auditing), CRISC (enterprise IT risk), and CGEIT (IT governance) — related credentials this site doesn't otherwise cover, worth knowing exist if your path bends toward audit or enterprise risk specifically rather than security-program management. For a full comparison against every other certification on this site, see the certifications hub; entry-level readers earlier in their career may want ISC2 Certified in Cybersecurity or CompTIA Security+ first, as a foundation to build years of experience on top of before CISM's requirement becomes realistic.

🎬 The promotion conversation
🐿️

Nutty the Squirrel: Your name's on the shortlist for AppSec manager. Six years writing SAST rules and gating merges — the technical case is solid. Do you have the management case too?

🦊

Foxy: Wait, why does that need a separate certificate? He's been running this pipeline's security for years already.

🐼

Master Panda: Running a pipeline's security and running a security program aren't the same job. One is "does this build pass." The other is "why does the board fund this team, and how do we prove it's working."

🐿️

Nutty the Squirrel: CISM tests exactly that — governance, enterprise-level risk, the program itself, and running incident response as a rehearsed plan, not an improvised one. Not one line of Rego anywhere on the exam.

🦊

Foxy: So none of the tooling knowledge counts for anything on exam day?

🐼

Master Panda: It counts toward the years of experience ISACA wants behind the exam. It's just not what the exam questions themselves are asking about.

✓ Checkpoint

1. What kind of exam is CISM, and how does that format differ from the CKS covered elsewhere on this site? 2. Name the four job-practice domains and their approximate weights. 3. Regrouped by function rather than curriculum order, what two even halves do those four domains fall into? 4. What does "sit-before-you-qualify" mean for CISM, and how is that different from the CKS's prerequisite gate? 5. If someone's near-term goal is to write more secure code and lead that effort specifically, which credential on this page is the closer match than CISM?

Check your answers
  1. CISM is a computer-based, multiple-choice exam with no performance-based or hands-on component. The CKS, by contrast, is 100% performance-based — live command-line tasks against real clusters, no multiple choice at all.
  2. Information Security Governance (17%), Information Security Risk Management (20%), Information Security Program (33%), and Information Security Incident Management (30%).
  3. "Build & govern the program" (Governance + Program = 50%) and "Assess risk & respond" (Risk Management + Incident Management = 50%) — an even split between design work and crisis-response leadership.
  4. You can sit and pass the CISM exam before meeting the experience requirement, but ISACA won't issue the certification itself until you submit verified evidence of the required experience, generally within five years of passing. CKS is the opposite shape — it won't even let you register for the exam without an active CKA already in hand, a hard block before you can attempt anything.
  5. CSSLP — it stays closest to the secure SDLC and secure-coding practice, unlike CISM's narrow focus on governance, risk, program, and incident management.