CISM Exam Guide — Certified Information Security Manager
29. Juli 2026~2 min read
CISM — Certified Information Security Manager Guide
The CISM from ISACA is the leading certification for information security managers. It validates your ability to manage, design, and oversee an enterprise's information security program.
Exam Overview
| Detail | Value |
|---|---|
| Provider | ISACA |
| Questions | 150 (multiple choice) |
| Length | 4 hours |
| Passing Score | 450 (on a scale of 200-800) |
| Price | ~$760 USD (member) / ~$575 USD (member) |
| Prerequisites | 5 years of security experience (3 years management) |
Domains
| Domain | Weight |
|---|---|
| Information Security Governance | 17% |
| Information Security Risk Management | 20% |
| Information Security Program | 33% |
| Incident Management | 30% |
Key Topics
Governance
- Enterprise governance, organizational structures, security strategy alignment
- Policies, standards, procedures, guidelines — differences and hierarchy
- Security awareness and training programs
- Metrics and reporting for executive management
Risk Management
- Risk assessment methodologies (qualitative vs quantitative)
- Risk appetite, tolerance, and capacity
- Business impact analysis (BIA)
- Risk treatment options (avoid, mitigate, transfer, accept)
- Third-party risk management
Program Development
- Security program architecture and resource planning
- Control frameworks (NIST, ISO 27001, COBIT)
- Security controls selection and implementation
- Security architecture, data classification, and asset management
- Compliance monitoring and reporting
Incident Management
- Incident response plan development and testing
- Business continuity and disaster recovery planning
- Incident response team structure and capabilities
- Forensic investigation and evidence collection
- Post-incident reviews and lessons learned
Bereit, dein Wissen zu testen?
Probiere unsere Übungsprüfungen mit Hunderten von realistischen Fragen aus.
Üben starten →