1
What the CISM Is — and Isn’t
The CISM is aimed at the security manager: the person accountable for building a program, managing risk in business terms, and answering to executives and the board. It assumes you already know the technology — what it tests is whether you can lead the function.
- It is not a hands-on technical exam. You will rarely choose a tool, command, or configuration.
- It is a judgment exam. Most questions ask ‘what should the security manager do first/best/next?’
- Right answers favor governance, policy, risk, and communication over technical fixes.
- The CISM complements technical credentials (e.g., CISSP, Security+) by adding the management layer.
💡 Exam TipWhen a question offers a technical fix and a management action (assess risk, escalate, update policy, inform stakeholders), the management action is almost always the better CISM answer — because the manager’s job is to direct the response, not perform it.
2
Exam Format & Scoring
- 150 multiple-choice questions, one best answer each.
- 4 hours to complete — roughly 96 seconds per question.
- Scored on a 200–800 scaled score; 450 is passing (about 60–65% of weighted points, not a fixed raw percentage).
- Delivered in English and other languages at testing centers and via remote proctoring.
- Unanswered questions are scored as incorrect — never leave a blank; flag and return instead.
🔎 In practiceAt ~96 seconds per question, pace matters. Make a first pass answering everything you know quickly, flag the hard ones, and return with your remaining time — the same strategy the capstone mock exams will drill.
3
The Four Domains & Their Weights
Every exam question maps to one of four domains. The weights tell you exactly where to invest study time — Domains 3 and 4 together are 63% of the exam.
| Domain | Title | Weight | Focus |
| 1 | Information Security Governance | 17% | Strategy, frameworks, board alignment |
| 2 | Information Security Risk Management | 20% | Risk lifecycle, asset valuation, treatment |
| 3 | Information Security Program | 33% | Program design, controls, operations, metrics |
| 4 | Incident Management | 30% | Response, continuity, recovery, improvement |
💡 Exam TipDomain 1 is the smallest at 17% — a common candidate mistake is over-studying governance theory. Give it a focused pass and pour your time into Domains 3 and 4, which decide the exam.
4
The Management Mindset — How to Answer
More candidates fail CISM for thinking like a technician than for lack of knowledge. Train the manager’s reflex: every decision is a business decision, justified by risk, owned by the right party, and aligned to objectives.
- Business first. The best answer protects business objectives and value, not just the asset.
- Govern, don’t do. The manager directs, assigns, escalates, and oversees — pick the option that does that.
- Risk drives priority. When in doubt, the first step is usually to assess or understand the risk before acting.
- Policy and people over point fixes. Durable answers change policy, awareness, or process — not just a single setting.
- Senior management owns risk acceptance. The security manager advises and recommends; the business accepts or rejects.
🔎 In practiceRead the stem for the role you are playing and the word that sets the bar — FIRST, BEST, NEXT, MOST, GREATEST. The CISM loves ‘first’ (what comes before action) and ‘best’ (the manager’s ideal). Match your answer to that word.
5
Eligibility & Maintenance
- Experience: five years of information security work experience, with at least three years in information security management across three or more of the four domains.
- Waivers: up to two years can be waived for certain credentials/degrees; experience must be earned within a 10-year window (or 5 years after passing).
- Pass first, qualify later: you may sit the exam before meeting the experience requirement and apply for certification within five years of passing.
- Maintenance: 120 CPE hours per three-year cycle (minimum 20/year) plus the annual maintenance fee — and continued adherence to the Code of Professional Ethics (next section).
6
The Code of Professional Ethics
Every CISM candidate and certificate holder agrees to ISACA’s Code of Professional Ethics. It is binding, and the exam tests it through scenarios — especially around serving stakeholders lawfully, confidentiality, and disclosing significant facts. Know these well enough to recognize the ethical choice under pressure.
The seven principles — members and certification holders shall:
- 1. Support the implementation of, and encourage compliance with, appropriate standards and procedures for the effective governance and management of enterprise IS/IT, including audit, control, security, and risk management.
- 2. Perform their duties with objectivity, due diligence, and professional care, in accordance with professional standards.
- 3. Serve in the interest of stakeholders in a lawful manner, while maintaining high standards of conduct and character, and not discrediting their profession or the Association.
- 4. Maintain the privacy and confidentiality of information obtained in the course of their activities unless disclosure is required by legal authority; such information shall not be used for personal benefit or released to inappropriate parties.
- 5. Maintain competency in their respective fields and undertake only activities they can reasonably expect to complete with the necessary skills, knowledge, and competence.
- 6. Inform appropriate parties of the results of work performed, disclosing all significant facts known to them that, if not disclosed, may distort the reporting of results.
- 7. Support the professional education of stakeholders in enhancing their understanding of the governance and management of enterprise IS/IT.
🔎 In practiceA breach is being quietly downplayed to avoid alarming customers and regulators. Principles 3 and 6 are decisive: serve stakeholders lawfully and disclose significant facts to the appropriate parties — the manager’s duty to stakeholders and the law outranks protecting the organization’s image.
💡 Exam TipEthics questions reward the choice that protects stakeholders and discloses the problem — never the one that conceals it or prioritizes personal or employer convenience over integrity, lawful conduct, and the public interest.
📚
Explore furtherEthics & Professional Conduct and the Ethics Challenge — interactive modules on professional codes of ethics and applying them to real dilemmas.
7
How to Use This Boot Camp
This five-day boot camp mirrors the proven structure of its CISA companion, adapted to CISM’s management focus: one domain per day, the heaviest domains split into two lessons, and Day 5 reserved for integrated practice and exam simulation.
- Work the lessons in order — each opens with vocabulary, builds through teaching sections with exam tips, and closes with a scored knowledge check.
- Spend the most time on Domains 3 and 4 (Lessons 4–7); they are 63% of the exam.
- Save the capstone (Lessons 8–9) for last — the cross-domain scenarios and mock exams work best after every domain is covered.
- Use the Practice Exam tool throughout to rehearse under time pressure and find your weak domains.