Certified Information Security Manager (CISM) at a glance
Certified Information Security Manager (CISM)
Status: ISACA states that the CISM Exam Content Outline will be updated effective 3 November 2026. Starting on that date, the exam will reflect the new outline.
| Certification | Certified Information Security Manager (CISM) |
|---|---|
| Number of questions | 150 |
| Duration | 4 hours (240 minutes) |
| Passing score | 450 or higher on a 200–800 scaled score |
| Question formats | Multiple-choice; one best answer from four options |
| Delivery | Computer-based at authorized PSI testing centers globally or as a remotely proctored exam |
| Exam cost | US$575 member; US$760 non-member |
| Languages | English, Spanish, Chinese-Simplified, Japanese, French, German |
| Certification validity | Maintained by meeting ISACA requirements, including at least 20 CPE hours annually and 120 CPE hours over a three-year reporting period |
| Retake policy | Up to four attempts within a rolling 12-month period. After an unsuccessful first attempt, candidates must wait 30 days before attempt 2, 90 days after attempt 2 before attempt 3, and 90 days after attempt 3 before attempt 4. The registration fee applies to each attempt. |
| Prerequisites | The exam is open to anyone interested in information security. CISM certification requires five or more years of professional information security management experience across at least three of the four CISM domains; the experience must fall within the 10 years preceding the certification application. Experience waivers are available for up to two years. |
CISM is designed for professionals responsible for managing, designing, overseeing, and assessing an enterprise information security function.
Skills measured and their weighting
| Skill area | Weight |
|---|---|
| Information Security Governance | 17% |
| Information Security Risk Management | 20% |
| Information Security Program | 33% |
| Incident Management | 30% |
Source: isaca.org — official CISM certification page. Figures were checked against ISACA’s official documentation. Confirm current details there before booking.
The full bank covers every domain, with timed mode and per-domain scoring.
CISM Practice Questions By Domains
4 domains covered1. Information Security Program
43 free questions available
2. Incident Management
38 free questions available
3. Information Security Risk Management
36 free questions available
4. Information Security Governance
33 free questions available
Practice the full exam, not a sample
Unlock the full bank and practise every domain end to end.
Unlock all 1191 questionsTake a Full-Length CISM Practice Test
150 questions · 4 hours · 450/800 to pass
Done with the domain drills? A full-length CISM practice test mirrors the real thing: 150 multiple-choice questions in 240 minutes, weighted across all four domains exactly the way ISACA weights them. It is the only honest way to find out whether your pacing holds up in hour three, when most candidates start second-guessing answers they got right in hour one.
Start the full practice exam →
Why Choose Edurely’s CISM Practice Test?
If you are moving from hands-on security work into program leadership, the CISM is the credential that proves it. But the exam does not test what you know how to configure. It tests how you would decide, which makes generic question banks close to useless. Here is what we do differently.
Built around the official ISACA job practice
Every question maps to one of the four domains in ISACA’s published exam content outline and to the weighting ISACA actually uses. That matters more than most candidates realize. Governance and risk feel like the “core” of CISM because they come first in the manual, but Information Security Program and Incident Management together account for roughly 63% of the questions you will see. Our bank is distributed the same way, so your practice time lands where the marks are.
Domain-by-domain practice, in ISACA’s own order
You can work on one domain at a time until the reasoning pattern clicks, then move on. Each of the four sets below is a standalone test with its own explanations:
- Information Security Governance: 17% of the exam. Security strategy, governance frameworks, roles and responsibilities, policies and standards, and aligning security objectives with business goals. This is the domain where the “right” answer is almost always the one that starts with the business, not the control.
- Information Security Risk Management: 20% of the exam. Risk identification, assessment and analysis, risk treatment options, risk ownership, and reporting risk to people who do not speak security. Expect many questions that hinge on who owns a decision rather than on what the decision is.
- Information Security Program: 33% of the exam. Building and running the program: resources, control design and selection, awareness and training, metrics, third-party management, and integrating security into business processes. The single heaviest domain on the exam.
- Incident Management: 30% of the exam. Incident readiness, classification, detection, containment, eradication, recovery, post-incident review, business continuity, and disaster recovery. Heavy on sequencing: what do you do FIRST, and what can wait?
Explanations that teach the CISM answer logic
Anyone can tell you option C is correct. The reason candidates fail CISM on their second attempt after passing every practice test is that they memorized answers rather than learning the decision hierarchy behind them. Every explanation in our bank tells you why the correct answer wins and why each distractor loses because, on CISM, all four options are usually defensible actions, and only one of them is the most defensible for a security manager at that moment.
Timed practice that mimics real exam pressure
You get a little under 100 seconds per question on the real exam. Our timed mode enforces that. Practicing untimed feels productive and tells you almost nothing about whether you will finish.
Free to start, updated for 2026
The 100 domain questions above are free and do not require an account. Content is reviewed against the current exam content outline, and the page shows the last review date so you know what you are getting. If you want the complete bank, all 1,191 CISM questions are available with 90 days of free updates.
Works on any device
Desktop, tablet, phone. Sessions are short enough to fit a commute, which is realistically where a lot of CISM study actually happens.
Important: the CISM exam changes on 3 November 2026
ISACA has confirmed an update to the CISM Exam Content Outline effective 3 November 2026. If you sit the exam on or before 2 November 2026, you take the current (2022) outline of the four domains and weightings described on this page. From 3 November onward, the updated outline applies.
What ISACA has signaled: a heavier emphasis on information security strategy and program development, plus two new content areas covering enterprise architecture and information security architecture. Updated ISACA prep materials went on sale in September 2026, and buying the current materials does not grant access to the new ones later.
What this means for you, practically:
- Already studying? Book before 2 November if you can. Your current preparation maps cleanly to the outline you would sit.
- Starting from zero now? Target Q1 2027, and study against the new outline once it is fully published.
- Either way, confirm the live weightings on ISACA’s official CISM page before you build a study plan. Anyone quoting exact new domain percentages ahead of ISACA’s full release is guessing.
Our domain tests remain useful across both versions. Governance, risk, program, and incident management are not going anywhere. We will flag any question set that shifts when the new outline is published.
How to Use These Practice Tests
A study routine that actually works, in the order we would run it:
- Take one domain test cold before you study anything. You need a baseline. Most people are much weaker in Governance than they expect, because it is the least like their day job.
- Read every explanation, including the ones on the questions you got right. If you picked the right answer for the wrong reason, that is a fail waiting to happen on a reworded question.
- Work the two heavy domains hardest. Program (33%) and Incident (30%) together account for nearly two-thirds of the exam. Do not split your study time evenly across four domains.
- Learn the sequencing rules. When a question asks what to do FIRST: assess and understand before you act, contain before you eradicate, and inform the risk owner before you make the call for them. When it asks what is MOST important, business alignment usually beats technical elegance.
- Then go full-length and timed. 150 questions, 4 hours, no pausing, no phone.
- Book the exam when you are consistently scoring 80%+ on fresh questions you have not seen before. Not 80% on a test you have already taken twice. That number is inflated by recall, and it is the most common reason people book too early.
- Pair practice with the concepts. If you want to see how CISM fits alongside ISACA’s other credentials before you commit, read our guide to the 5 certifications offered by ISACA.
Frequently Asked Questions About the CISM Exam
What is the CISM certification?
CISM (Certified Information Security Manager) is a management-level credential from ISACA for professionals who design, govern and run enterprise information security programs. It has been offered since 2002 and has been earned by more than 107,000 people. Unlike technical certifications, CISM tests judgment: whether you can align security with business objectives, manage risk, build a program, and lead incident response, not whether you can configure a firewall.
What’s on Edurely’s CISM practice test?
All four domains of the current ISACA exam content outline are: Information Security Governance, Information Security Risk Management, Information Security Program, and Incident Management. You can practice each domain individually using the links above, or take a full-length timed exam that mirrors the real 150-question format. Every question includes a written explanation of the correct answer and why the other three options are wrong.
How many questions are on the real CISM exam?
150 multiple-choice questions, with a 4-hour (240-minute) time limit. That works out to roughly 96 seconds per question. There are no simulations, drag-and-drop items, or performance-based tasks. Every question is a standard multiple-choice question with four options.
What is the passing score for CISM?
450 on a scaled range of 200 to 800. The scaled score is a statistical conversion, not a percentage of correct answers, so 450 does not translate to “56% correct.” ISACA does not publish the raw number of correct answers needed, and it varies slightly between exam forms to account for difficulty. Most experienced candidates aim for roughly 70–75% correct on practice material as a safety margin.
What are the four CISM domains and their weightings?
Under the current outline: Information Security Governance (17%), Information Security Risk Management (20%), Information Security Program (33%), and Incident Management (30%). Program and Incident Management together make up 63% of the exam, which is where most of your study time should go. Each links to a dedicated practice set above.
Is the CISM exam changing in 2026?
Yes. ISACA has confirmed a new CISM Exam Content Outline, effective 3 November 2026, as part of its Job Practice Analysis cycle. The four domains remain, but with a stronger emphasis on information security strategy and program development, plus new content on enterprise architecture and information security architecture. Exams on or before 2 November 2026 use the current outline. Check ISACA’s official page for the final published weightings.
How hard is the CISM exam?
Hard, but not for the reason people expect. The individual concepts are not technically deep; a working security manager will recognize almost every term. The difficulty is that CISM questions routinely offer four actions that are all reasonable and ask which is MOST appropriate, BEST, or should be done FIRST. You are being scored on prioritization, not recall. Candidates with hands-on engineering backgrounds tend to struggle most because their instinct is to fix the technical problem, whereas the exam wants them to assess impact and inform the risk owner.
What is the CISM pass rate?
ISACA does not publish official pass rate statistics for CISM. Third-party estimates commonly place first-attempt pass rates somewhere between 50% and 60%, but these are extrapolations rather than confirmed figures. Treat any site quoting an exact official pass rate with skepticism.
How long should I study for the CISM exam?
For someone already working in security management, 8 to 12 weeks at 8–10 hours per week is a realistic range. Candidates coming from a purely technical background usually need longer, often 3 to 4 months, because the mindset shift takes more time than the content. What matters more than total hours is doing enough practice questions to internalize the answer logic: 1,000+ questions with explanations is a reasonable target.
Do I need work experience to take the CISM exam?
No, you can sit the exam without any experience. But you cannot become certified until you document five years of information security management experience, including at least three years in three or more of the four CISM domains. That experience must fall within the ten years before your application, or within five years of passing the exam. Many candidates take the exam early and complete the experience requirement afterward.
What experience waivers does ISACA accept for CISM?
Up to two years of the five-year requirement can be waived. Common substitutions include holding CISA or CISSP in good standing, a postgraduate degree in information security or a related field, and certain other security credentials and skill-based certificates. Waivers apply only to the general experience requirement; the three years of security management experience across three domains cannot be waived. Confirm the current substitution list with ISACA, as it is updated periodically.
How much does the CISM certification cost?
The exam registration fee is $575 for ISACA members and $760 for non-members. There is also a $50 certification application fee upon passing. ISACA membership costs roughly $135 plus a local chapter fee, so joining before registering usually pays for itself immediately given the $185 exam discount. Budget another $200–$500 for study materials, and factor in the annual maintenance fee once certified. Total realistic cost to get certified: around $825–$1,200, depending on membership status.
Where do I take the CISM exam?
At an authorized PSI test center, or from home or your office via remote proctoring. Both deliver identical content and scoring. Remote proctoring has stricter environmental requirements: a clear desk, a private room, a system compatibility check beforehand, and no scratch paper in either format beyond what the proctor permits. Test centers eliminate the risk of technical failure, which many candidates consider worth the trip for a four-hour exam.
How many times can I retake the CISM exam?
Up to four times in a rolling 12-month period, with the full registration fee payable each attempt. There is no free retake. ISACA exam registrations are valid for 12 months from the date of purchase, and you can reschedule without penalty up to 48 hours before your appointment. Within 48 hours, or if you no-show, the fee is forfeited.
When do I get my CISM results?
You receive a preliminary pass/fail result on screen immediately after finishing. The official score report follows by email, typically within about ten working days, and includes a domain-by-domain breakdown of your performance. If you fail, that breakdown is the most valuable study guide you will get. It tells you exactly which domain sank you.
What happens after I pass the CISM exam?
Passing is not the same as being certified. You must submit a certification application with documented, verified work experience, pay the $50 application fee, and agree to ISACA’s Code of Professional Ethics and CPE policy. You have five years from your pass date to apply. Miss that window and the passing score expires.
How do I maintain my CISM certification?
Earn a minimum of 20 CPE hours per year and at least 120 CPE hours over each three-year reporting cycle, pay the annual maintenance fee, and comply with ISACA’s Code of Professional Ethics. You may also be selected for a CPE audit, so keep documentation of every activity you claim. CPEs can come from training, conferences, webinars, teaching, publishing, and relevant volunteer work.
Does CISM expire?
The certification does not expire on a fixed date, but it will be revoked if you fail to meet the CPE requirements or stop paying the annual maintenance fee. Keep both current, and the credential remains valid indefinitely.
CISM vs CISSP: Which should I take?
They overlap but serve different career paths. CISSP (ISC2) is broader and more technical, covering eight domains from cryptography to software development security, and is often the better fit for practitioners and architects. CISM is narrower and purely managerial, focusing on governance, risk, program management, and incident response, and is a better fit if you are targeting security manager, GRC lead, or CISO-track roles. CISSP requires five years of experience across two of eight domains; CISM requires five years of experience specifically in security management. Plenty of senior people hold both, and holding CISSP can waive up to two years of the CISM experience requirement.
CISM vs CISA: what’s the difference?
Both are ISACA credentials, but CISA (Certified Information Systems Auditor) is for people who audit and assess IT systems and controls, while CISM is for people who build and run the security program. CISA suits internal audit, compliance, and assurance roles; CISM suits security management. If you audit security programs for a living, CISA first. If you own one, CISM. You can read more in our overview of the certifications ISACA offers.
CISM vs CRISC: which is more useful?
CRISC (Certified in Risk and Information Systems Control) goes deeper into enterprise IT risk, specifically risk identification, assessment, response, and control monitoring. CISM covers risk as one of four domains alongside governance, program, and incident management. If your role is dedicated risk management, CRISC is more targeted. If your role is running a security function, of which risk is one part, CISM is broader and generally carries more weight in security leadership hiring.
Is CISM worth it?
For the right role, yes. CISM consistently appears near the top of industry salary surveys for IT and security certifications, and it is frequently listed as a required or preferred credential in job postings for security managers, GRC leads, and CISOs, particularly in finance, healthcare, government contracting, and consulting. It is less useful if you are early-career or staying in a hands-on technical track, where CISSP, the Security+ family, or vendor certifications give better returns. Salary figures vary widely by region, sector, and seniority, so treat any single number you see quoted with caution.
Does CISM meet DoD requirements?
CISM has long been an approved credential for information assurance management roles under the US Department of Defense workforce framework, including IAM Level II and Level III positions, and it carries over into the DoD 8140 qualification framework that replaced 8570.01-M. Because the qualification matrix is updated periodically, verify CISM’s current listing for your specific work role against the DoD Cyber Exchange before relying on it for a job requirement.
Is CISM good for beginners?
No, and ISACA does not intend it to be. The exam assumes you have sat in meetings where security budgets were argued over and incidents were escalated. You can pass it without experience by studying hard, but you will not be able to certify until you accumulate five years of qualifying experience. If you are starting out, Security+ or CISA is a more sensible first step.
Are free CISM practice questions enough to pass?
They are enough to diagnose where you stand and to train the answer logic, which is the hardest part of CISM. They are not a substitute for understanding the underlying material. The candidates who fail after strong practice scores are almost always the ones who memorized specific questions rather than the reasoning. Use practice tests to identify gaps, then close them with the ISACA Review Manual or a structured course, then come back and test again with fresh questions.
Are these real CISM exam questions?
No. ISACA exam content is confidential and protected, and any site claiming to sell actual live exam questions is offering something that violates ISACA’s certification agreement. Using it can invalidate your result and revoke your certification. Our questions are original, written to match the style, difficulty, and domain weighting of the real exam. That is the only legitimate way practice material works, and honestly, it is also the more effective way, since the real exam is drawn from a large rotating pool you cannot memorize your way through.
How do I answer CISM “MOST”, “BEST,” and “FIRST” questions?
Three habits handle most of them. First, read the question as a security manager, not an engineer. If one option is technical and the other is about governance, communication, or business impact, the second is usually the right choice. Second, for “FIRST” questions, follow the natural sequence: understand the situation, assess impact, then act, then communicate. You cannot make a good decision on information you have not gathered. Third, when a question involves a decision about accepting or treating risk, the answer is almost always that the risk owner or business owner decides, not the security manager. Our explanations indicate which of these patterns each question tests.
What score should I be hitting on practice tests before I book the exam?
Consistently 80% or better on questions you have not seen before, across all four domains, not just your strong ones. A high average that hides a 60% in Governance is a warning sign, because you cannot choose which domain the exam weights. Retaking a test you have already worked through will inflate your score by 10–15 points through recall alone, so always judge readiness on fresh material.
Can I use these CISM practice tests on my phone?
Yes. All the domain tests and the full-length exam run in any modern mobile browser, with no app install and no account needed for the free questions.