CISM Exam Domains and Weights
CISM covers Information Security Governance, Information Security Risk Management, Information Security Program, and Incident Management.
- For exams before November 3, 2026, the weights are 17%, 20%, 33%, and 30%.
- For appointments on or after that date, they are 18%, 20%, 33%, and 29%.
- The domain headings remain, while task statements are updated.
On this page8 sections
Select the outline version by exam date
ISACA has announced an updated CISM job practice outline effective November 3, 2026. Candidates sitting before that date use the prior outline and its 17/20/33/30 weights. Candidates testing on or after November 3 use the revised outline and 18/20/33/29 weights. Registration date and study start date do not set the version; the scheduled exam date does.
The four domain names stay the same, but task statements have been revised. ISACA's transition announcement describes additional attention to enterprise architecture and information security architecture, as well as changes to management responsibilities. Therefore, simply memorizing the four weights is not enough for a late-2026 candidate. Download the outline that matches the appointment date and study the task statements within each domain.
| CISM domain | Before Nov. 3, 2026 | On/after Nov. 3, 2026 | What the domain asks you to manage |
|---|---|---|---|
| Information Security Governance | 17% | 18% | Direction, accountability, strategy, policies, and alignment with enterprise objectives |
| Information Security Risk Management | 20% | 20% | Identification, assessment, treatment, monitoring, and communication of security risk |
| Information Security Program | 33% | 33% | Establishing, resourcing, implementing, measuring, and improving security capabilities |
| Incident Management | 30% | 29% | Readiness, response coordination, communications, recovery, and learning from incidents |
Weights represent the relative amount of exam content assigned to each domain. They are useful for allocating preparation effort, but they do not guarantee a fixed number of questions or create a separate pass score for each area. The candidate guide says the overall scaled result is based on total scored questions answered correctly; domain feedback is informational.
Information Security Governance
Governance establishes how the organization directs and oversees information security. Study how security objectives relate to business strategy and risk appetite, who has authority to approve policies and accept risk, and how leadership receives useful performance and risk information. Governance also means defining accountability across business units, security teams, suppliers, and executive bodies.
Consider a company expanding into a regulated market. Security governance must identify applicable obligations, set oversight responsibilities, and ensure that strategy and funding reflect the new business context. A security manager can recommend controls and report risks, but an authorized business leader makes decisions about residual business risk. A question may ask which governance action comes first; establishing responsibility and decision criteria usually precedes selecting a technical safeguard.
For the revised outline, compare each task statement to your preparation notes for strategy, governance, architecture, and accountability. Enterprise architecture and security architecture are connected but not interchangeable. Enterprise architecture describes how business capabilities, information, applications, and technology fit together. Security architecture ensures protective requirements and controls are integrated into those structures. An organization needs both views to make a coherent security decision.
Information Security Risk Management
Risk management begins with context: assets, business processes, threat scenarios, vulnerabilities, likelihood, impact, existing controls, and the organization's criteria. The manager makes sure owners understand exposure and that treatment decisions fall within delegated authority. Treatment choices commonly include mitigation, avoidance, transfer, or acceptance. Monitoring matters because threats, systems, suppliers, and business priorities change.
Suppose a business unit wants to accept a cloud provider's default logging configuration to accelerate a launch. Before recommending a control change, the security manager should determine what monitoring is required by policy and risk criteria, who owns the business risk, and whether the provider can meet the need. If a gap remains, the accountable owner evaluates treatment. A tool purchase alone does not constitute risk acceptance or management.
Practice translating technical statements into business impact. 'An administrative account lacks multifactor authentication' is a condition. The risk analysis asks which assets the account can reach, how likely misuse is, what impact follows, and which controls reduce exposure. The CISM perspective includes communicating this clearly so that an owner can decide and oversee treatment.
Information Security Program
At 33 percent, the Information Security Program is the largest domain in both outline versions. It covers program objectives and scope, policies and standards, control selection, roles, staffing, awareness, suppliers, measurement, and continual improvement. The program should be proportionate to business objectives and risk. The right program is not necessarily the one with the most controls; it is one with accountable owners and evidence that intended outcomes are achieved.
A program manager should connect initiatives to identified risks, establish priorities, assign responsibility, secure resources, communicate requirements, and define meaningful indicators. For example, counting how many employees completed training is an activity measure. Measuring whether reported phishing incidents are triaged within the target period may say more about operational performance. No metric is useful if its audience cannot make a decision from it.
Vendor and third-party management belongs in the program view when suppliers support important information processes. Assess the service and data involved, assign internal accountability, define contractual and operational controls, monitor performance, and plan for exit or disruption. Outsourcing a service does not outsource the organization's responsibility for understanding its exposure.
Incident Management
Incident Management covers preparation, detection and response coordination, escalation, communications, recovery, and post-incident improvement. Plans should identify roles, authority, contact paths, dependencies, evidence handling, and criteria for activating response. Exercises help expose gaps before a real event, but a completed exercise is not proof that every team member can perform under pressure.
In an incident, the manager should establish a reliable picture of the event, coordinate the designated response structure, preserve information, and communicate through authorized channels. Containment, service availability, legal obligations, and customer trust can compete. The best action depends on facts and delegated authority. After recovery, identify root causes and assign improvements with owners and due dates.
An incident question may contain pressure from an executive to make an immediate public claim. If scope is not confirmed, the manager should coordinate fact finding and approved communications rather than overstate what is known. Speed matters, but inaccurate communication can create additional harm. The answer should preserve response effectiveness and fulfill applicable notification duties as facts and policy require.
A connected example across all four domains
A retailer plans a new cloud service that processes loyalty-account data. Governance sets the business objective, assigns a data owner, defines oversight, and establishes risk tolerances. Risk Management assesses supplier access, data retention, outage exposure, and relevant threat scenarios. The Security Program funds and assigns controls, such as access review, logging, supplier monitoring, and recovery tests. Incident Management defines how the retailer and provider will coordinate a suspected account compromise.
If the provider later reports suspicious access, governance determines who can make material business decisions; risk management evaluates the changing exposure; the program supplies the controls and response resources; incident management coordinates containment, evidence, communications, and recovery. A question may focus on one domain, but the most defensible action recognizes the organization-wide decision path.
How to study the domain weights
Use the weights as a baseline for study time, then adjust for your own gaps. Since Program has the largest share, it deserves sustained attention. Governance is smaller but essential for reasoning about authority and alignment. Risk Management underpins choices across the other domains. Incident Management requires understanding both plans and decisions under uncertainty. Avoid spending all your time on the largest domain or treating the others as optional.
For each task statement, make a compact study card with four prompts: what decision is being made, who is accountable, what evidence or criteria supports it, and how will the result be monitored? Then work one original scenario that combines domains. This forces you to move beyond flashcard recognition and practise the management perspective.
If your appointment is on or after November 3, compare every task in the revised outline with your existing materials. Mark additions and changed emphasis, especially architecture-related tasks. If your appointment is earlier, do not switch outlines just because the updated materials are newer. Prepare against the version that applies to your date, and recheck official materials if you reschedule across the transition.
Common outline errors
- Using the revised 18/20/33/29 weights for an exam before November 3, 2026, or the old 17/20/33/30 weights for a later exam.
- Assuming the domain names staying the same means all tasks and emphasis are unchanged.
- Treating weights as an exact number of items or a domain-specific pass mark.
- Studying security controls without learning governance, risk ownership, program measurement, and response authority.
- Assuming that a vendor, technical team, or security manager automatically owns every business risk.
The outline is a map of management work. Match the version to the appointment date, use weights to guide effort, and learn the decisions behind each task. Your goal is to explain how governance sets direction, risk management supports choices, the security program delivers capability, and incident management prepares the organization to respond and recover.
Common questions
What are the four CISM domains?
Information Security Governance, Information Security Risk Management, Information Security Program, and Incident Management.
What are the CISM domain weights before November 3, 2026?
The weights are 17%, 20%, 33%, and 30% in domain order: Governance, Risk Management, Program, and Incident Management.
What are the revised CISM domain weights?
For exams on or after November 3, 2026, the weights are 18%, 20%, 33%, and 29%, in the same domain order.
Does the 33% Program weight guarantee a set number of questions?
No. Weights describe relative content coverage and do not guarantee a fixed question count or create a separate passing threshold by domain.
Which outline should I use if I reschedule across November 3?
Use the outline tied to the new appointment date. Exams on or after November 3, 2026 use the revised outline.