The CISM certification overview covers what the exam tests and who it is for. This guide goes a level deeper: what to study first, the sub-topics ISACA actually tests within each domain, the frameworks you need to know cold, and how to manage the exam itself.
CISM is written from the perspective of the manager who owns the outcome, not the engineer who implements a single control. That framing should drive how you study. For every topic, ask what a responsible leader would evaluate, decide, or escalate first, rather than how you would technically implement it.
Study in this order. It follows how the domains build on each other, not just their exam weight.
Start here even though it is the smallest domain. It sets the authority, direction, and reporting structure that every other domain assumes already exists. You cannot reason about risk ownership or program design without first knowing who decides and on what basis.
With governance in place, layer on how risk is found, sized, treated, and monitored. This domain is where the exam most often tests judgment over recall. Expect scenario questions asking who should own a given risk decision.
The largest domain, and where governance and risk get operationalized: resources, controls, third parties, metrics, and reporting. Budget the most study time here. It is a third of the exam on its own.
Finish with readiness, response, and recovery. This domain rewards sequencing knowledge, knowing what a manager does first, second, and third under pressure, more than any list of tools.
Domains 3 and 4 together are 63 percent of the exam, so if your study time is limited, protect the hours you have allocated to them first.
Two sub-areas, per ISACA's official content outline: Enterprise Governance (organizational culture, legal, regulatory and contractual requirements, organizational structures, roles and responsibilities) and Information Security Strategy (strategy development, information governance frameworks and standards, strategic planning including budgets, resources, and business cases).
What to actually master: how to build a business case that gets senior leadership to fund and commit to a security strategy, how governance integrates into corporate governance rather than sitting beside it, and how organizational culture and legal context shape what a good strategy looks like for a specific enterprise. There is no universal right answer independent of context.
Common trap: picking the technically strongest control option when the question is actually testing whether you would secure a business case and leadership buy-in first.
Two sub-areas: Information Security Risk Assessment (emerging risk and threat landscape, vulnerability and control deficiency analysis, risk assessment and analysis) and Information Security Risk Response (risk treatment and response options, risk and control ownership, risk monitoring and reporting).
What to actually master: the distinction between assessing a risk and owning the decision about it. The exam frequently separates who identifies a risk from who is accountable for accepting, transferring, mitigating, or avoiding it. Also know the difference between a control deficiency, a gap in a designed control, and a vulnerability, a weakness that could be exploited. These get tested as distinct concepts.
Common trap: choosing the most thorough risk-analysis method when the scenario is actually asking who should be accountable for the resulting decision.
Two sub-areas, and the most sub-topic-dense domain on the exam. Information Security Program Development covers program resources (people, tools, technologies), information asset identification and classification, industry standards and frameworks, policies, procedures and guidelines, and program metrics. Information Security Program Management covers control design and selection, control implementation and integration, control testing and evaluation, security awareness and training, management of external services (providers, suppliers, third and fourth parties), and program communications and reporting.
What to actually master: the full arc from what controls we need through how we prove they work. Control design, implementation, and testing and evaluation are tested as three distinct stages, not one activity. Third and fourth-party risk management is a frequently underweighted study area relative to how often it is tested.
Common trap: treating we implemented the control as equivalent to we tested and evaluated the control. The exam draws a hard line between these.
Two sub-areas. Incident Management Readiness covers the incident response plan, business impact analysis, business continuity plan, disaster recovery plan, incident classification and categorization, and incident management training, testing and evaluation. Incident Management Operations covers incident management tools and techniques, incident investigation and evaluation, containment methods, incident response communications (reporting, notification, escalation), eradication and recovery, and post-incident review practices.
What to actually master: the difference between a business impact analysis, which quantifies impact and drives recovery priorities, and a business continuity or disaster recovery plan, which operationalize the response. Then the correct sequence during a live incident: classify, contain, investigate, communicate and escalate, eradicate, recover, review. Post-incident review is commonly under-studied but regularly tested.
Common trap: jumping straight to eradicating the threat in a scenario question before containment and proper escalation. Sequencing errors are the most common way candidates lose points in this domain.
You do not need to be a practitioner in any of these. CISM tests whether you know when and why a manager would reference each one, not how to implement them.
No. You can sit the exam with no prior experience. You need five years of information security management experience across at least three of the four domains to hold the certification afterward, with substitutions available for up to two years via qualifying degrees and credentials.
Managerial. It assumes technical literacy but tests management judgment: who owns a decision, what business objective is at risk, and what process produces a defensible result.
Domain 3, Information Security Program, at 33 percent, followed by Domain 4, Incident Management, at 30 percent. Together they are nearly two thirds of the exam.
450 on a scaled range of 200 to 800. Not all 150 questions are scored, since some are unscored pretest items, so you cannot infer your standing mid-exam.
Four attempts in a rolling 12-month period, with a 30-day wait after your first attempt and 90-day waits after each attempt following. Plan your prep timeline around that if you are not confident going in.
150 multiple-choice questions in 4 hours, roughly 96 seconds per question if you use the full time. Pacing is rarely the binding constraint; judgment under the manager rather than engineer framing is.
Domain weights and sub-topics are sourced from ISACA's official CISM Exam Content Outline, matching the domain summaries published on the CISM overview page. Confirm current fees, CPE requirements, and exam details at isaca.org before you register.