Day 1 — Morning · Orientation

Orientation & Exam Strategy

CISM is a management exam, not a technical one. Before your first study hour, master how the exam is built and scored — and the single habit that decides pass or fail: answering every question as a business-aligned security manager, never as a technician.

Session: Morning, Day 1 Duration: ~3 hrs Coverage: Exam Format & Mindset Knowledge Check: 5 Questions

Overview

Think like a security manager, not a technician

The Certified Information Security Manager credential is ISACA’s premier certification for the people who design, oversee, and assess an enterprise security program — not the people who configure the firewalls. That distinction drives everything. On the CISM exam, two answers can both be technically correct, yet only the one a business-aligned manager would choose is right. This orientation sets the rules of the game: the exam’s structure and scoring, the four domains and their weights, the eligibility and ethics requirements, and — most importantly — the mindset shift from practitioner to manager that every later lesson reinforces.

ℹ️ Independence NoticeThis is an independent educational resource — not affiliated with, endorsed by, or sponsored by ISACA. CISM® is a registered trademark of ISACA. Content is based on publicly available ISACA documentation and the CISM Job Practice effective 2022 (current as of 2026); always confirm the live exam content outline at isaca.org before you register.

Learning Objectives

By the end of this lesson you will be able to…

Key Terms

Orientation vocabulary

👈 Tap a card to flip it. These are the foundational terms and exam facts every CISM candidate must own from day one.

Lesson Content

Study the material

1

What the CISM Is — and Isn’t

The CISM is aimed at the security manager: the person accountable for building a program, managing risk in business terms, and answering to executives and the board. It assumes you already know the technology — what it tests is whether you can lead the function.

  • It is not a hands-on technical exam. You will rarely choose a tool, command, or configuration.
  • It is a judgment exam. Most questions ask ‘what should the security manager do first/best/next?’
  • Right answers favor governance, policy, risk, and communication over technical fixes.
  • The CISM complements technical credentials (e.g., CISSP, Security+) by adding the management layer.
💡 Exam TipWhen a question offers a technical fix and a management action (assess risk, escalate, update policy, inform stakeholders), the management action is almost always the better CISM answer — because the manager’s job is to direct the response, not perform it.
2

Exam Format & Scoring

  • 150 multiple-choice questions, one best answer each.
  • 4 hours to complete — roughly 96 seconds per question.
  • Scored on a 200–800 scaled score; 450 is passing (about 60–65% of weighted points, not a fixed raw percentage).
  • Delivered in English and other languages at testing centers and via remote proctoring.
  • Unanswered questions are scored as incorrect — never leave a blank; flag and return instead.
🔎 In practice

At ~96 seconds per question, pace matters. Make a first pass answering everything you know quickly, flag the hard ones, and return with your remaining time — the same strategy the capstone mock exams will drill.

3

The Four Domains & Their Weights

Every exam question maps to one of four domains. The weights tell you exactly where to invest study time — Domains 3 and 4 together are 63% of the exam.

DomainTitleWeightFocus
1Information Security Governance17%Strategy, frameworks, board alignment
2Information Security Risk Management20%Risk lifecycle, asset valuation, treatment
3Information Security Program33%Program design, controls, operations, metrics
4Incident Management30%Response, continuity, recovery, improvement
💡 Exam TipDomain 1 is the smallest at 17% — a common candidate mistake is over-studying governance theory. Give it a focused pass and pour your time into Domains 3 and 4, which decide the exam.
4

The Management Mindset — How to Answer

More candidates fail CISM for thinking like a technician than for lack of knowledge. Train the manager’s reflex: every decision is a business decision, justified by risk, owned by the right party, and aligned to objectives.

  • Business first. The best answer protects business objectives and value, not just the asset.
  • Govern, don’t do. The manager directs, assigns, escalates, and oversees — pick the option that does that.
  • Risk drives priority. When in doubt, the first step is usually to assess or understand the risk before acting.
  • Policy and people over point fixes. Durable answers change policy, awareness, or process — not just a single setting.
  • Senior management owns risk acceptance. The security manager advises and recommends; the business accepts or rejects.
🔎 In practice

Read the stem for the role you are playing and the word that sets the bar — FIRST, BEST, NEXT, MOST, GREATEST. The CISM loves ‘first’ (what comes before action) and ‘best’ (the manager’s ideal). Match your answer to that word.

5

Eligibility & Maintenance

  • Experience: five years of information security work experience, with at least three years in information security management across three or more of the four domains.
  • Waivers: up to two years can be waived for certain credentials/degrees; experience must be earned within a 10-year window (or 5 years after passing).
  • Pass first, qualify later: you may sit the exam before meeting the experience requirement and apply for certification within five years of passing.
  • Maintenance: 120 CPE hours per three-year cycle (minimum 20/year) plus the annual maintenance fee — and continued adherence to the Code of Professional Ethics (next section).
6

The Code of Professional Ethics

Every CISM candidate and certificate holder agrees to ISACA’s Code of Professional Ethics. It is binding, and the exam tests it through scenarios — especially around serving stakeholders lawfully, confidentiality, and disclosing significant facts. Know these well enough to recognize the ethical choice under pressure.

The seven principles — members and certification holders shall:

  • 1. Support the implementation of, and encourage compliance with, appropriate standards and procedures for the effective governance and management of enterprise IS/IT, including audit, control, security, and risk management.
  • 2. Perform their duties with objectivity, due diligence, and professional care, in accordance with professional standards.
  • 3. Serve in the interest of stakeholders in a lawful manner, while maintaining high standards of conduct and character, and not discrediting their profession or the Association.
  • 4. Maintain the privacy and confidentiality of information obtained in the course of their activities unless disclosure is required by legal authority; such information shall not be used for personal benefit or released to inappropriate parties.
  • 5. Maintain competency in their respective fields and undertake only activities they can reasonably expect to complete with the necessary skills, knowledge, and competence.
  • 6. Inform appropriate parties of the results of work performed, disclosing all significant facts known to them that, if not disclosed, may distort the reporting of results.
  • 7. Support the professional education of stakeholders in enhancing their understanding of the governance and management of enterprise IS/IT.
🔎 In practice

A breach is being quietly downplayed to avoid alarming customers and regulators. Principles 3 and 6 are decisive: serve stakeholders lawfully and disclose significant facts to the appropriate parties — the manager’s duty to stakeholders and the law outranks protecting the organization’s image.

💡 Exam TipEthics questions reward the choice that protects stakeholders and discloses the problem — never the one that conceals it or prioritizes personal or employer convenience over integrity, lawful conduct, and the public interest.
7

How to Use This Boot Camp

This five-day boot camp mirrors the proven structure of its CISA companion, adapted to CISM’s management focus: one domain per day, the heaviest domains split into two lessons, and Day 5 reserved for integrated practice and exam simulation.

  • Work the lessons in order — each opens with vocabulary, builds through teaching sections with exam tips, and closes with a scored knowledge check.
  • Spend the most time on Domains 3 and 4 (Lessons 4–7); they are 63% of the exam.
  • Save the capstone (Lessons 8–9) for last — the cross-domain scenarios and mock exams work best after every domain is covered.
  • Use the Practice Exam tool throughout to rehearse under time pressure and find your weak domains.

Scored Knowledge Check

Test your orientation

Five questions on the exam and the mindset. Choose the best answer, then submit for your score and the rationale — and start practicing the manager’s reflex now.

Q1.Which statement BEST captures how to approach CISM exam questions?

Question 1 options
Correct: C. CISM rewards management judgment: the best answer reflects a business-aligned manager weighing risk, cost, and objectives — not the most technical or the most risk-averse option. Why the others fall short: A the most technically thorough option is a technician’s answer; B eliminating risk regardless of cost ignores the cost/benefit balance; D the hands-on engineer’s choice is the practitioner view, not the manager’s.

Q2.What is the passing score on the CISM exam?

Question 2 options
Correct: B. The exam is reported on a 200–800 scaled score, and 450 is the passing mark — not a fixed raw percentage. Why the others fall short: A the exam isn’t scored as a raw percentage; C 600/900 isn’t the CISM scale; D 450 is a scaled score, not a raw count out of 150.

Q3.Which two domains together account for the largest share of the exam?

Question 3 options
Correct: A. Domain 3 (Information Security Program, 33%) and Domain 4 (Incident Management, 30%) total 63% — the bulk of the exam. Why the others fall short: B Governance (17%) and Risk (20%) total only 37%; C Risk and Incident total 50%; D Governance and Incident total 47% — all below Program (33%) plus Incident (30%).

Q4.A serious vulnerability is discovered in a production system. From a CISM perspective, what should the security manager do FIRST?

Question 4 options
Correct: A. The manager’s first move is to understand the business risk and engage the right decision-makers; the technical remediation is directed and prioritized from that assessment, not performed reflexively. Why the others fall short: B patching immediately is the technician’s reflex, skipping risk assessment; C shutting the system down may harm the business more than the vulnerability; D re-imaging is a hands-on fix, not the manager’s first step.

Q5.Who is ultimately responsible for accepting a residual information security risk?

Question 5 options
Correct: D. The security manager advises and recommends, but accepting (or rejecting) residual risk is a business decision owned by senior management / the business risk owner. Why the others fall short: A the security manager advises but doesn’t own the risk; B IT implements controls but doesn’t accept business risk; C internal audit provides assurance, not risk acceptance.