All certifications
ISACALive

CISM

Certified Information Security Manager

Management-focused credential covering security governance, risk management, program development, and incident management, built for security leaders.

Exam length
240 min
Pass score
450/800 (scaled)
Questions
150
Domains
4

Suggested prep: 8–12 weeks · Difficulty: Expert

Domain breakdown

Official weights from the ISACA exam outline. We track your mastery on each domain individually so you know where to focus.

01Information Security Governance17%
02Information Security Risk Management20%
03Information Security Program33%
04Incident Management30%

Try a real CISM question

Pulled straight from the free tier. Every question in the bank cites a public source you can verify.

Which statement best describes the primary purpose of information security governance, as distinct from information security management?

  1. AEstablishing the strategic direction, oversight, and accountability structures that ensure security supports business objectives
  2. BAllocating staff and executing the board-approved security plans on a day-to-day basis
  3. CMeasuring control effectiveness and reporting operational metrics to the CISO
  4. DSelecting and tailoring the control baseline for each individual information system
Show answer and explanation

Correct answer

Establishing the strategic direction, oversight, and accountability structures that ensure security supports business objectives

Governance sets strategic direction, oversight, and accountability so security enables the mission, while management carries out the resulting decisions. Allocating staff to execute plans, selecting and tailoring control baselines, and measuring and reporting control effectiveness are all management functions that operate within the direction governance establishes, not the governance function itself.

Source: NIST SP 800-100, Information Security Handbook: A Guide for Managers

CISM FAQ

How many questions are on the CISM exam?

The ISACA CISM exam has 150 questions and runs 240 minutes. A passing score is 450/800 (scaled).

What domains does CISM cover?

4 domains, per the official ISACA outline: Information Security Governance (17%), Information Security Risk Management (20%), Information Security Program (33%), Incident Management (30%).

How long should I study for CISM?

Typical prep time is 8–12 weeks, depending on your experience. TierOne's spaced-repetition queue is built for short daily sessions, so progress compounds even on a busy schedule.

Can I try CISM practice questions for free?

Yes. The free tier includes 50 real CISM practice questions with cited sources, the Question of the Day, and the AI tutor (5 explanations per day). No credit card required.

Is there a pass guarantee?

Yes. If you fail your CISM exam after 30 or more days on Pro, send us your score report and choose 3 free months or a full refund.

Ready to start prepping for the CISM?

Sign up free in 30 seconds. Take a Quick Quiz to see where you stand. The platform handles the rest.

Not affiliated with or endorsed by ISACA. CISM is a trademark of its owner.