1
Domain 1 — Governance (17%)
Core principle: security exists to enable the business, and accountability lives at the top. Governance directs, aligns, and measures; the board owns it and cannot delegate accountability.
- Five outcomes: strategic alignment, risk management, value delivery, resource optimization, performance measurement.
- Strategy flows business → IT → IS → policy → standards → procedures → metrics; gap analysis comes first.
- Frameworks (COBIT EDM vs. management, ISO 27001 PDCA, NIST CSF) are chosen to fit context.
- Metrics: KGI (goal), KPI (performance), KRI (rising-risk warning).
2
Domain 2 — Risk Management (20%)
Core principle: risk is owned by the business; security identifies, analyzes, and recommends, but the business accepts. Risk = probability × impact, managed as a continuous lifecycle.
- Lifecycle: identify → analyze (qualitative/quantitative) → treat → monitor & report.
- Quantitative: SLE = AV × EF; ALE = SLE × ARO; buy a control when it costs less than the ALE it removes.
- Treatment: mitigate, transfer, avoid, accept — transfer (insurance) moves cost, not accountability.
- Data owner classifies and values assets; residual risk above appetite is escalated, never silently accepted.
3
Domain 3 — Security Program (33%)
Core principle: the program executes the strategy — chartered, resourced, and architected — with controls chosen on a risk basis and improved continuously. The largest domain.
- Charter and senior-management mandate come before tools; controls trace to objectives and risk.
- Control types (preventive/detective/corrective) and categories (administrative/technical/physical); use all three, in depth.
- People and third parties are first-class risks — culture, role-based training, due diligence, right-to-audit, cloud shared responsibility (data stays the customer’s).
- Measure in business terms; sustain with continuous improvement (PDCA) and secure-by-design delivery.
4
Domain 4 — Incident & Resilience (30%)
Core principle: when prevention fails, management response and resilience decide the outcome. The manager directs; specialists execute. Second-largest domain.
- IR lifecycle: prepare → detect & analyze → contain → eradicate → recover → learn; preparation matters most, containment precedes eradication.
- Preserve evidence and chain of custody; notify the right parties within legal timeframes; escalate critical incidents immediately.
- The BIA drives continuity: RTO (downtime), RPO (data loss), MTD (outer limit, RTO < MTD).
- An untested plan or backup is worthless; BCP is owned by the business, DRP by IT, under crisis management.
5
Cross-Domain Scenarios & the Decision Pattern
The hardest questions span domains. Use one repeatable pattern: identify the role you play (manager), read the qualifying word (FIRST/BEST/NEXT/MOST), and choose the option that is business-aligned, risk-based, owned by the right party, and aligned to objectives.
🔎 In practiceScenario: a critical vulnerability is found in a customer-facing system mid-quarter. Weak answer: patch immediately (technician). Strong answer: assess the business risk, follow the change/incident process, brief the risk owner, and prioritize remediation by impact — spanning risk (D2), program (D3), and incident (D4) at once.
🔎 In practiceScenario: a vendor that processes customer data suffers a breach. Weak answer: assume the vendor is responsible. Strong answer: invoke the incident plan, exercise the right-to-audit and contractual notification terms, assess residual risk, and disclose to regulators/customers as required — the data owner is still accountable (D2, D3, D4).
💡 Exam TipIf two answers both look correct, eliminate the one that has you acting as a technician, accepting risk on the business’s behalf, or maximizing security regardless of cost. The remaining option is almost always the CISM answer.
6
The 30/60/90-Day Study Plan
Anchor your preparation to your weakest domains and to the blueprint weights. A simple, weighted countdown beats unfocused re-reading.
🔎 In practiceWeight your effort by domain size. A weak Domain 3 or 4 (33% and 30%) costs far more than a weak Domain 1 (17%). When you review practice results, fix the heavy domains first — the practice exam’s domain breakdown is built for exactly this.
Days 1–30 — Build coverage
- Work every lesson once; build or review the vocabulary until the terms are automatic.
- Take short, single-domain practice sets to find your weak areas early.
- Start a personal ‘trap log’ of questions you missed and why — almost always a technical-vs-management slip.
Days 31–60 — Deepen the heavy domains
- Concentrate on Domains 3 and 4; re-work the program, incident, and continuity material.
- Move to mixed, timed practice sets; review every rationale, not just the score.
- Convert recurring misses into one-line rules you can recall under pressure.
Days 61–90 — Simulate and polish
- Run full, timed 150-question simulations to build stamina and pacing.
- Re-test only your weak domains between simulations until they stabilize.
- Taper in the final days; confirm logistics and rest.
7
Exam-Day Playbook
Pacing and disciplined reading win marks that knowledge alone leaves on the table. Run the exam the way you ran your simulations.
- Pace: ~96 seconds per question; first pass for the ones you know, flag and return for the rest.
- Read the stem twice: identify your role (manager) and the qualifying word (FIRST/BEST/NEXT/MOST) before the options.
- Eliminate, then choose: remove the technician and risk-acceptance traps; pick the business-aligned, risk-based answer.
- Answer everything: no blanks — an unanswered question scores as wrong.
- Trust your prep: first instincts trained on the mindset are usually right; change an answer only with a clear reason.
💡 Exam TipWhen a question feels like it has two right answers, it is testing the management distinction. Re-read for who should act and what should happen first — the manager’s coordinating, business-aligned move is the intended answer.
8
The Manager’s Mindset — One Last Time
Every domain reduces to the same habit. If you internalize one thing, make it this decision pattern.
- Business first — the answer protects business objectives and value, balanced against cost.
- Risk-based — assess and prioritize by risk before acting.
- Right owner — the business owns and accepts risk; security advises and recommends.
- Govern, don’t do — direct, assign, escalate, and oversee rather than perform.
🔎 In practiceIf you are ever unsure, ask: ‘What would a business-aligned security manager do, and who should own this decision?’ That single question resolves the majority of CISM items.
9
Official ISACA Resources
Use authoritative ISACA materials to go deeper than any single course, and to keep the language consistent with the exam.
- CISM Review Manual — the primary domain reference aligned to the Job Practice.
- CISM Questions, Answers & Explanations (QAE) database — large pools of exam-style items with rationale.
- ISACA Online Review Course — structured, self-paced coverage of all four domains.
- ISACA Engage community and local chapter study groups for peer support and study cadence.