CISM Master Guide 2026
CISM is ISACA's information security management certification.
- The exam has 150 multiple-choice questions and four hours of testing.
- The outline changes for exams on or after November 3, 2026, so candidates should match study materials to their appointment date.
- Passing the exam and earning the credential are separate steps: certification also requires qualifying management experience and an approved application.
On this page10 sections
- What CISM measures
- Choose the outline for your appointment date
- The four domains
- How the exam works
- Scoring, results, and retakes
- Registration, location, and cost
- Eligibility to sit and certification after a pass
- A practical study approach
- After certification: ethics and maintenance
- How to choose your next step
What CISM measures
CISM stands for Certified Information Security Manager. ISACA positions it for professionals who manage, design, oversee, or assess an organization's information security program. Its perspective is managerial: connect security decisions to business objectives, risk appetite, governance, resources, and accountability. The exam tests whether you can select a defensible management action in a security scenario, not whether you can configure a particular vendor product.
The credential can be relevant to security managers, governance and risk leads, program owners, incident leaders, and experienced practitioners moving toward management responsibilities. It is a professional certification, not a government license and not a guarantee of a particular job title. Employers define their own experience and role requirements. ISACA's certification rules also mean that passing the exam alone does not make a candidate a CISM.
| Candidate question | Published answer |
|---|---|
| Exam format | 150 multiple-choice questions; four hours |
| Current outline before November 3, 2026 | Governance 17%, Risk Management 20%, Security Program 33%, Incident Management 30% |
| Outline for appointments on or after November 3, 2026 | Governance 18%, Risk Management 20%, Security Program 33%, Incident Management 29% |
| Exam access | Candidates may register and sit without first meeting the certification experience requirement |
| Certification experience | Five years of information security management experience across at least three of four domains, subject to approved substitutions/waivers |
| Application deadline | Apply within five years after passing the exam |
| Maintenance | 120 CPE hours per three-year cycle, at least 20 each year; annual maintenance fee applies |
Choose the outline for your appointment date
CISM is in the middle of an outline transition. ISACA's current outline applies before November 3, 2026. The revised outline is effective for exam dates beginning November 3, 2026. The four domain names stay the same, but the weighting changes from 17/20/33/30 to 18/20/33/29 percent. The transition release also describes updated task statements and greater attention to enterprise architecture, information security architecture, and contemporary management responsibilities.
Use the date of the actual appointment, not the date you bought a book, started a course, or registered, to select the version. Someone testing October 30 uses the current outline even if preparation began in September. Someone testing November 3 uses the revised outline even if they registered earlier. ISACA said new preparation materials aligned to the revised outline became available September 1, 2026. A candidate who has a choice near the transition should weigh readiness and access to current materials before moving an appointment.
A modest weight change does not mean that a domain has disappeared. Governance increases one percentage point, Incident Management decreases one point, and the other two weights stay at 20 and 33 percent. The more useful study implication is to read the revised task statements. A test plan made from an older outline may omit new emphasis even though the domain headings look familiar.
The four domains
| Domain | Before Nov. 3 | On/after Nov. 3 | Management question |
|---|---|---|---|
| Information Security Governance | 17% | 18% | Are security direction, authority, strategy, and accountability aligned with enterprise objectives and risk? |
| Information Security Risk Management | 20% | 20% | How should the organization identify, assess, treat, monitor, and communicate security risk? |
| Information Security Program | 33% | 33% | How should management establish, resource, implement, and measure a program of controls? |
| Incident Management | 30% | 29% | How should the organization prepare for, respond to, communicate about, and learn from incidents? |
Governance concerns direction and oversight. A board or executive committee sets expectations, approves risk appetite, assigns accountability, and receives information that supports decisions. The security manager translates that direction into a strategy and governance structure, while business owners remain responsible for the risks their processes create. A strong answer usually clarifies authority and aligns security priorities to business objectives rather than treating security as a separate technical island.
Risk Management starts with the organization's context and criteria. A security manager identifies assets, threats, vulnerabilities, likelihood, impact, and existing controls, then helps owners choose treatment: mitigate, transfer, avoid, or accept within delegated authority. Assessment results should be understandable to decision makers and revisited when conditions change. A risk register is useful only if owners, decisions, and follow-up are clear.
The Security Program domain is the largest. It covers establishing a program, selecting and operating controls, managing people and suppliers, setting metrics, and continually improving. Management makes the program fit the organization: a small firm with regulated customer data has different staffing and assurance needs from a global service provider. A control can be technically sound and still fail if no one owns it, funds it, or measures whether it works.
Incident Management covers readiness as well as response. Plans need defined authority, roles, escalation criteria, communication paths, resources, and recovery dependencies. During an incident, management must preserve reliable facts, coordinate the response, meet applicable notification obligations, and restore services safely. Afterward, lessons should lead to assigned improvements. The exam may test the order of decisions, especially when containment, evidence preservation, business continuity, and communication compete.
How the exam works
The published format is a computer-based exam with 150 multiple-choice questions and four hours of testing time. ISACA describes questions as scenario oriented. The candidate guide is the authority for current appointment policies, breaks, identification, remote-proctor conditions, and rescheduling. The public description does not establish a CAT format, hands-on lab, or performance simulation, so study materials should not promise those mechanics.
Four hours for 150 questions averages 96 seconds per question. That average includes reading scenarios and reviewing marked items, so it is a planning aid rather than an official per-question limit. Practice reading the final sentence first: identify whether the prompt asks for the best first action, a primary responsibility, a risk treatment, or a program outcome. Then read the scenario for the facts that affect that choice.
Management questions often reward sequence and authority. For instance, an executive reports a major service disruption and asks the security manager to announce that customer data were stolen. The first responsible move is to coordinate the established incident process, validate what is known with the response team, and use approved communications channels. Announcing an unverified breach can mislead customers and compromise response work. The manager should communicate promptly, but accuracy and delegated authority matter.
Scoring, results, and retakes
ISACA reports exam scores on a scaled range from 200 to 800, and 450 or higher passes. A scaled score is not a raw percentage correct: 450 does not mean that a candidate answered a particular percentage of questions correctly. The scale supports comparable reporting across exam forms. ISACA includes scored and pretest items, but does not identify which items are unscored. Domain-level results are informational; the overall score is based on the total number of scored items answered correctly, and domain percentages are not used to calculate the result.
The candidate guide describes a preliminary result at the end of the test and a later official score report through the candidate's ISACA account and email. It also sets attempt limits and waiting periods for retakes. Check the guide for the policy in force on your test date, since account procedures and fees can change. After a failed attempt, use the domain feedback to choose specific remediation rather than repeating the same study routine unchanged.
Registration, location, and cost
Registration is handled through ISACA. Candidates pay the exam fee, then use the provider scheduling process to choose an available appointment. Current delivery options include authorized test centers and remote proctoring where offered. A candidate should distinguish the registration eligibility window from the appointments that happen to be available; a six-month window does not guarantee a preferred date, language, or local center.
The 2026 ISACA candidate guide lists US$575 for members and US$760 for nonmembers for CISM. Those amounts are exam registration prices, not a full certification budget. A candidate may also pay for preparation material, a retake, membership, the certification application, and annual maintenance. Taxes, currency conversion, and local checkout conditions can affect the final amount. Membership can be worthwhile for other benefits, but compare the actual cost and term rather than assuming it always saves money.
The candidate guide states that registration is nonrefundable and nontransferable, subject to the published rescheduling policy. Appointment changes made sufficiently early may be permitted without penalty; late changes can forfeit the fee. Read the current candidate guide before paying and schedule only after confirming the test date, delivery mode, time zone, identification requirements, and preparation readiness.
Eligibility to sit and certification after a pass
ISACA allows candidates to take the CISM exam before they have accumulated the professional experience required for certification. That makes the exam accessible to people building toward management work, but it does not waive the credential's experience requirement. The exam pass is one part of the application, and it has a five-year application window.
To earn CISM, ISACA requires five years of professional information security management experience across at least three of the four domains. The 2026 Candidate Guide says experience waivers are available up to a maximum of two years. A waiver is conditional, not automatic, and an applicant must still document experience that covers the required domains. Use the current certification application instructions to determine which qualifications qualify and what evidence ISACA requires. A candidate should map actual responsibilities to the domains and retain evidence of dates and duties. Job title alone does not establish that work qualifies.
The certification application includes experience verification and a one-time processing fee. Applicants also agree to ISACA's professional ethics requirements and continuing education policy. A candidate who passes now but needs more experience should record the pass date, work periods, domain coverage, and verifier contacts. This is more reliable than waiting several years and trying to reconstruct old duties from memory.
A practical study approach
Start by writing down your appointment date and the outline version that applies. Download the matching official outline and candidate guide. Turn every task statement into a question you should be able to answer. For each area, explain the management objective, the decision owner, the evidence needed, and how success would be measured. This transforms a list of topics into useful retrieval practice.
Next, take a diagnostic set and classify each miss. Was it a knowledge gap, a misread qualifier, an overly technical answer, or a failure to recognize the proper management sequence? Record the reason and the next action. If you miss a risk treatment question because you jumped to implementation before identifying the risk owner, the remedy is to practice decision authority and treatment criteria, not memorize another control list.
A ten-week plan can be adapted to your available time. In weeks one and two, review Governance and Risk Management, define terminology, and make a short decision map. In weeks three through five, study the Security Program and build examples of program objectives, controls, metrics, suppliers, and improvement cycles. In weeks six and seven, study Incident Management from readiness through lessons learned. In weeks eight and nine, mix domains in timed scenario sets and review every explanation. In week ten, take full-length timed practice, repair repeated reasoning errors, and reduce new material.
The schedule is a framework, not an official required study duration. Someone with security management experience may need more time on formal governance language or risk methods. A technically experienced analyst may need additional work on business alignment, program ownership, and executive communication. Someone new to security management should reserve time to learn the work context instead of relying on question memorization.
Original worked question
A company has approved a new customer portal. A risk assessment identifies that the portal will store sensitive personal data, but the project team has not assigned a risk owner or agreed on acceptable residual risk. The launch date is close. What should the CISM most appropriately recommend first? A. Buy a penetration test and proceed if no critical vulnerabilities are found. B. Ask the business owner to accept or treat the documented risk using the organization's risk criteria before release. C. Delay all security work until the portal is in production. D. Transfer the risk to the cloud provider through the contract.
Best answer: B. The risk needs an accountable owner and a decision against approved criteria. A penetration test can provide useful evidence, but it does not decide whether the business should accept residual risk. Waiting until production is too late, and a contract does not transfer all accountability for customer data or business impact. The manager should ensure the right owner makes an informed decision and that required controls and approvals are documented.
After certification: ethics and maintenance
CISM is maintained through continuing professional education and an annual maintenance fee. ISACA's policy requires 120 CPE hours in a three-year reporting period, with at least 20 hours in each year. The credential holder reports qualifying activities and follows ISACA's audit and ethics requirements. CPE can include relevant professional learning and contributions under policy categories; keep records that show what you did, when, and how it relates to professional competence.
The annual maintenance fee listed for CISM is US$45 for an ISACA member and US$85 for a nonmember. Fees can be reduced for holders of multiple ISACA certifications under the published policy. Annual fees and three-year CPE are separate obligations. Missing one year's minimum cannot be repaired simply by reaching 120 hours at the end of the cycle. Keep a calendar and review the current maintenance policy each year.
CISM knowledge can support work in security governance, risk oversight, program management, and incident leadership, but the certification does not replace practical judgment. A credential holder still needs to adapt controls to organizational context, communicate uncertainty accurately, and preserve management accountability. It is most useful when paired with experience that demonstrates these responsibilities.
How to choose your next step
If your exam date is before November 3, work from the current outline. If it is on or after that date, use the revised outline and its updated task statements. If you are deciding whether to sit before the transition, compare your readiness against the actual scheduled date and the materials you can study. For a targeted concern, use a focused guide on eligibility, registration, domains, study planning, or certification requirements.
Common questions
Can I take the CISM exam before I have five years of experience?
Yes. ISACA permits candidates to sit before meeting the experience requirement. You still need qualifying experience and an approved application to earn the CISM credential.
Which CISM outline applies in 2026?
The existing outline applies to exam dates before November 3, 2026. The revised outline applies to exam dates on or after November 3, 2026. Choose based on your appointment date.
How many questions and how much time are on the CISM exam?
The published exam format is 150 multiple-choice questions in four hours.
Does passing the exam automatically make me a CISM?
No. You must submit an application, meet the information security management experience requirement or applicable approved substitutions, and satisfy ISACA's professional requirements.
How much continuing education does CISM require?
ISACA requires 120 CPE hours in each three-year cycle and at least 20 hours in each year, plus the applicable annual maintenance fee.