Advanced ISACA · Exam CISM

ISACA CISM Study Guide

The CISM (Certified Information Security Manager) is ISACA's security-leadership credential — governance, risk, security-program management, and incident management from the manager's chair. Where CISSP proves breadth across security practice, CISM proves you can run a security program: it's the credential for security manager, GRC lead, and CISO-track roles.

Overview

Level

Advanced

Vendor

ISACA

Audience

Mid-career security and IT professionals moving from doing the work to running the program — SOC leads, security engineers stepping into management, GRC analysts, and IT managers taking over security responsibility. Like CISSP, it's experience-gated: this is not a beginner cert, and chasing it at year two of your career is premature.

Why get CISM

CISM is consistently a top-5 paying certification in industry salary surveys and appears in security-manager and CISO-track postings almost interchangeably with CISSP — but it stakes out different ground: management and governance rather than technical breadth. It's DoD 8140-recognized, HR-filter strong, and it certifies the exact skill hiring committees struggle to verify any other way: that you can align a security program with business risk rather than just configure controls. If your trajectory is security manager → director → CISO, this is the credential built for that road.

Salary expectations

Typical salary range

$140,000 – $170,000

Skillsoft's salary reports put CISM holders around $155K–$167K average in the U.S. — regularly top-5 among all certs tracked. Read that honestly: CISM holders average 10+ years of experience and skew into management, so the number reflects who holds it, not a raise the letters confer. The relevant BLS anchors bracket it: Information Security Analysts at $124,910 median, Computer & Information Systems Managers around $171K (May 2024).

When to get CISM

When you have (or can see) five years of infosec experience including three years of security management across at least three of the four domains. Waivers trim up to two years off the general requirement — a current CISSP or CISA waives two, a postgrad security degree waives two — but the three years of management experience cannot be waived. You can sit the exam early and apply for certification within five years of passing, so the smart play for a senior IC eyeing management is: pass now, certify when the management years land.

Exam details

Exam Quick Reference

Exam Code
CISM
Vendor
ISACA
Level
Advanced
Duration
4 hours (240 minutes)
Format
150 multiple-choice questions at PSI test centers or via remote online proctoring. Scored 200–800; 450 to pass (roughly 60–65% of scored items). Your exam eligibility window is 6 months from registration — schedule inside it or forfeit the fee.
Questions
150 questions

Renewal: Annual maintenance: $45 members / $85 non-members, plus 120 CPE hours per 3-year cycle (minimum 20 reported each year), subject to random audit. Passing the exam does NOT certify you — you must apply within 5 years with verified experience and a $50 processing fee.

Skills covered

Information Security Governance (17%)

  • Building a security strategy aligned to organizational goals
  • Governance frameworks, roles, and accountability structures
  • Security policy hierarchy and standards development
  • Reporting security posture to boards and executives
  • Legal, regulatory, and contractual requirement integration

Information Security Risk Management (20%)

  • Risk identification, assessment, and analysis methods
  • Risk treatment: mitigate, transfer, accept, avoid
  • Risk appetite, tolerance, and business alignment
  • Third-party and supply-chain risk management
  • Monitoring, reporting, and keeping risk registers honest

Information Security Program (33%)

  • Building and running the security program end to end
  • Security budgets, resources, and roadmap management
  • Control selection, implementation, and measurement
  • Security awareness and training programs
  • Metrics, KPIs, and program reporting that executives act on

Incident Management (30%)

  • Incident response planning and organizational readiness
  • Classification, escalation, and communication during incidents
  • Business continuity and disaster recovery integration
  • Post-incident review and program improvement
  • Running the response as a manager — not the keyboard

Step-by-step study path

This sequence reflects what consistently works. Follow it in order—don't skip ahead.

  1. 1

    Check the experience math before anything

    Five years in infosec, of which three years must be security MANAGEMENT across 3+ of the 4 domains. Waivers (CISSP/CISA, postgrad degree) trim up to two years off the general portion only — the three management years are non-negotiable. If they're not in sight yet, this cert can wait.

  2. 2

    Mind the November 2026 outline change

    The CISM exam content outline updates effective 3 November 2026, and ISACA has said current study-material purchases won't include revised content. Either book your exam before the switch or wait and buy the new-edition materials — don't get caught mid-cycle with stale prep.

  3. 3

    Take ISACA's free practice quiz first

    Before spending a dollar, take the free official 10-question quiz. It calibrates you to the 'ISACA way' — risk-based, business-aligned, manager-first answers — which decides this exam more than technical knowledge does.

  4. 4

    Work a primary text

    The official CISM Review Manual is the source of truth but famously dry; Peter Gregory's All-in-One guide covers the same ground more readably. Pick one and finish it — most candidates need 2–4 months part-time.

  5. 5

    Drill the official QAE database

    The ISACA Questions, Answers & Explanations database (1,000+ questions, 12-month sub) is the single most-recommended purchase by people who passed — the questions come from the exam's own body. Consistently scoring 70%+ there is the community's readiness benchmark.

  6. 6

    Rewire your instincts to the manager's chair

    The #1 reason technical people fail CISM: answering as the engineer. The exam wants the risk-based, business-aligned, delegate-and-govern answer every time. When two options look right, pick the one a security MANAGER does — assess risk, align to business, communicate up.

  7. 7

    Register smart, then sit the exam

    Join ISACA first if you're buying any study materials — the member discount on exam plus QAE plus manual beats non-member pricing by $100–300 all-in. Register only when ready: the 6-month eligibility window starts at purchase and is non-refundable. Four hours, 150 questions — pace at ~90 seconds each.

  8. 8

    Apply for certification — passing isn't holding

    After passing, apply within five years: verified experience, a supervisor's sign-off, and the $50 processing fee. Plenty of people pass and stall here — don't. The letters only count when ISACA approves the application.

Ready for a structured course?

A top-rated course covers every CISM exam domain in order. See the paid resources section below for options and pricing.

View course options →

Free resources

Vouchers & exam cost

$575 member / $760 non-member — no third-party vouchers exist. The membership math favors joining first (~$145/yr international dues + chapter dues): roughly break-even on the exam alone, then $100–300 ahead once you buy the QAE database or Review Manual at member pricing. Retakes are full price, so don't register until you're genuinely close.

Frequently asked questions

CISM or CISSP — which one should I pursue?

Different chairs at the same table. CISSP is broader and more technical-leadership flavored; CISM is squarely management — governance, risk, running the program. Job postings frequently list them interchangeably, so for pure HR-filter value they're comparable. Pick by trajectory: architect/technical leadership → CISSP; security manager/CISO-track/GRC → CISM. Holding CISSP first also waives two years of CISM's general experience requirement.

Can I take the CISM exam without the experience?

Yes — you can sit the exam any time and apply for certification within five years of passing. The gate is at the application: five years of infosec experience including three years of security management across 3+ domains, verified by a supervisor. The management years cannot be waived, so plan honestly around them.

Why do technical people fail CISM?

Because they answer as engineers. The exam rewards the 'ISACA answer' — risk-based, business-aligned, always the manager's move — over the technically correct one. When two options both look right, the winner assesses risk, aligns to the business, or communicates upward. The official QAE question bank exists precisely to drill this reflex, which is why passers call it near-mandatory.

Is ISACA membership worth it for the exam?

Usually yes, if you're buying any study materials. Non-member exam: $760. Member exam plus dues: roughly the same all-in — but membership then saves ~$100 on the QAE database, $30 on the Review Manual, and $40/year on maintenance, plus free CPE webinars that make renewal cheaper long-term.

Does CISM expire?

It's maintained annually: $45 member / $85 non-member fee due each January, plus 120 CPE hours per 3-year cycle with at least 20 per year. ISACA runs random CPE audits, so keep documentation. Fall out of compliance and the credential is revoked — budget the lifetime cost, not just the exam.

What's this about the exam changing in late 2026?

ISACA's updated CISM exam content outline takes effect 3 November 2026, with updated study materials arriving from September 2026 — and ISACA has said current purchases won't include revised content. If you're testing in late 2026, either sit the exam before the switch or wait and buy the new materials. Don't straddle it.

Ready to study?

Start with the free resources above, then add a top-rated course and practice exams when you're ready to test yourself.