CISM
Certified Information Security Manager
Security program management, risk, governance, and incident governance. The manager / CISO-track signal.
› Quality score
Four-axis SecProve rubric, each 0–10. SecProve editorial assessment — each axis carries a written justification so you can push back on any single call without dismissing the whole score.
› Market signals
public, citable inputs to the recognition score› Built for these roles
› Exam format
150 multiple-choice questions over 4 hours, English plus several other languages. Pearson VUE proctored. Application requires verified work-experience attestation in addition to passing the exam.
ISACA member $575 / non-member $760. 4 attempts per rolling 12-month window.
› Recertification
120 CPE hours over the three-year cycle (avg 40/yr, minimum 20/yr) plus the $45/yr maintenance fee for ISACA members ($85/yr non-members). Late renewal triggers a one-year suspension before reinstatement.
› 3-year cost of ownership
Excludes study materials, training, retake risk, and lost-wage opportunity. Use as a floor estimate.
› NICE Framework work roles
The NIST NICE work-role IDs this cert maps to. NICCS lookup.
› Core domains covered
The 3 domains this cert is centrally about. Passing the exam demonstrates working knowledge of each.
Risk frameworks (NIST RMF, ISO 31000, FAIR), policy development, audit, regulatory compliance, third-party risk.
Cyber risk quantification, board communication, security program development, budget & ROI.
IR playbooks, memory/disk/network forensics, chain of custody, malware analysis.
› Also touched
Present in the blueprint but not the primary focus — you’ll be introduced but shouldn’t expect depth.
Data classification, encryption-at-rest/in-transit, DLP, tokenization, privacy-by-design, plus the regulatory stack (GDPR, CCPA, HIPAA) that sets the bar.
SBOM, vendor risk assessment, software supply chain attacks, dependency management.
Reference architectures, control frameworks (NIST SP 800-53, CIS Controls), secure-by-design patterns, threat modeling, trust-boundary design, technology standards.
› Known coverage gaps
Domains this cert does not meaningfully address. Plan follow-up learning here if your role touches any of them.
› Prerequisites
Five years of information-security management experience, with at least three years across the CISM job practice areas.
- Security governance and program management
- Risk management frameworks
- Incident management governance
› Progression
requiredrecommendedWhere this cert fits in the typical learning path. Required edges are vendor-gated; recommended edges reflect de facto industry progression.
No vendor-gated prereqs.
No certs require this one.
› Study materials
Curated starting points. Not exhaustive — vet each against your learning style and the current exam version.
- CISM Review Manual, 16th Ed. — ISACA
- CISM QAE Database — ISACA
- ISACA Official CISM Online Course
- Phil Martin CISM Exam Prep (Udemy)
- ISACA CISM QAE (1000+ questions)
- Pocket Prep CISM
› Version & lifecycle
Four domains: governance, risk management, program development, incident management.
› Salary signal
Information security manager / director, US, 5+ years.
ISACA Salary Survey + Robert Half Salary Guide · 2024 · US base only · p25–p75 range
› How it compares
Broader senior-IC + architecture coverage vs CISM's narrower security-management focus.
↔ Compare side-by-side› Careers that commonly pursue this cert
Manage risk, ensure regulatory compliance, and build governance frameworks. Where security meets business strategy.
Lead security strategy, communicate risk to the board, and build security programs. Executive-level cybersecurity leadership.
See this cert’s domains highlighted on the interactive map, or compare it against the rest of the catalog.