From your first practice question to exam day, Getcertkey covers the entire CISM journey: a free demo, 1193 practice questions in three formats, a full year of free updates, and a clear refund policy. Preparing for the ISACA Certified Information Security Manager exam has rarely been this straightforward.
ISACA CISM Exam Overview:
| Certification Vendor: | ISACA |
|---|---|
| Exam Name: | Certified Information Security Manager |
| Exam Number: | CISM |
| Exam Format: | Multiple Choice |
| Related Certifications: | CISM |
| Available Languages: | English, French, Japanese, Spanish, Chinese-Simplified, German |
| Exam Duration: | 240 minutes |
| Exam Price: | $575 (Member) / $760 (Non-Member) |
| Real Exam Qty: | 150 |
| Passing Score: | 450 (out of 800) |
| Certificate Validity Period: | 3 years (requires maintenance fees and CPE) |
| Sample Questions: | ![]() |
| Exam Way: | Computer-based testing at authorized PSI testing centers or remotely proctored. |
| Pre Condition: | To earn the CISM certification, candidates must pass the exam and possess a minimum of five years of information security work experience with a minimum of three years of information security management work experience in three or more of the CISM domains. Substitutions and waivers for general information security experience are available. |
| Official Syllabus URL: | https://www.isaca.org/credentialing/cism |
ISACA CISM Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| Topic 1: Information Security Risk Management | 20% | - Monitor and communicate the information security risk posture - Determine appropriate risk treatment options - Establish and/or maintain a process for information asset identification, classification, risk assessment and ownership - Identify legal, regulatory, organizational and other applicable compliance requirements - Identify and/or recommend risk treatment options - Integrate risk management into business and IT processes - Ensure that risk assessments, vulnerability assessments and threat assessments are performed consistently, at appropriate times, and to identify acceptable risk - Evaluate information security controls to determine whether they are appropriate and effectively mitigate risk |
| Topic 2: Information Security Governance | 17% | - Establish, monitor, evaluate and report information security management metrics - Obtain commitment from senior management and other stakeholders for the information security program - Establish and/or maintain information security policies to guide the development of standards, procedures and guidelines in alignment with enterprise goals and objectives - Develop business cases to support investments in information security - Identify internal and external influences to the organization that affect the information security strategy and program - Establish and/or maintain an information security governance framework and supporting processes to ensure that the information security strategy is aligned with the goals and objectives of the organization - Define and communicate the roles and responsibilities for information security throughout the organization |
| Topic 3: Information Security Incident Management | 30% | - Develop and implement processes to ensure the timely identification of information security incidents - Establish and maintain communication plans and processes to manage communication with internal and external entities - Establish and maintain an organizational definition of, and severity hierarchy for, information security incidents - Organize, train and equip teams to effectively respond to information security incidents - Establish and maintain an incident response plan to ensure an effective and timely response to information security incidents - Establish and maintain incident escalation and notification processes - Establish and maintain processes to investigate and document information security incidents - Test, review and revise the incident response plan |
| Topic 4: Information Security Program Development and Management | 33% | - Establish, communicate and maintain organizational information security standards, guidelines, procedures and other documentation - Develop and maintain a security awareness, training and education program for all stakeholders - Integrate information security requirements into organizational processes - Establish and/or maintain the information security program in alignment with the information security strategy - Monitor and manage the information security program - Align the information security program with the operational objectives of other business functions - Establish and maintain information security architectures (people, process, technology) - Identify, acquire and manage information security requirements for internal and external resources (services, partners, and suppliers) |
CISM Exam FAQs for 2026 Candidates
Which certification does the CISM exam lead to?
The CISM exam is the official ISACA exam behind the Isaca Certification certification, validating the skills measured by the ISACA Certified Information Security Manager credential. It sits at the Manager level of the ISACA certification program. It also connects to CISM, so the knowledge you build here carries over to those tracks as well.
How many questions are on the CISM exam, and how much time do I get?
The CISM exam contains 150 questions to be completed within 240 minutes. Before exam day, divide the available time by the question count to work out a comfortable per-question pace, and mark any item that eats into it so you can return later instead of getting stuck. Timed sessions in the Getcertkey test engines make that pacing automatic — run at least two full-length mock exams under the clock so time pressure never becomes the reason you drop points.
What score do I need to pass the CISM exam, and what does it cost?
The passing score for the CISM exam is 450 (out of 800), and the official registration fee is $575 (Member) / $760 (Non-Member). Retakes are not discounted — every new attempt means paying the full fee again — so it pays to measure yourself before you book. Work through the 1193 practice questions on Getcertkey, sit a timed practice test, and schedule your exam only when your scores are consistently comfortable. That simple habit is the cheapest exam strategy there is.
Are there any prerequisites for the CISM exam?
To earn the CISM certification, candidates must pass the exam and possess a minimum of five years of information security work experience with a minimum of three years of information security management work experience in three or more of the CISM domains. Substitutions and waivers for general information security experience are available. Requirements can change when ISACA revises its certification program, so confirm the current eligibility rules on the official exam page before you register.
Can I try the CISM practice questions before I buy?
Yes. Getcertkey provides a free CISM PDF demo so you can review the question style and answer quality before purchasing. Every purchase also includes 365 days of free updates — if ISACA revises the exam during that period, the updated material reaches you at no cost. Once the free-update year ends, you can extend your update service at a 50% discount.
What if I fail the CISM exam, and how is my order delivered?
Every ISACA Certified Information Security Manager purchase on Getcertkey is covered by a 100% money-back guarantee with clear conditions: if you take the corresponding exam within 60 days of your purchase and do not pass, you can claim a full refund by submitting a scanned copy of your exam enrollment slip and your official score report as a PDF within two days of the exam date; claims are processed within seven days of submission. The guarantee does not apply to exams taken within three days of purchase, to material that was downloaded but never used in an exam attempt, or to free products and expired orders, and the candidate name must match the payer name. If you would rather not take a refund, you can instead exchange your purchase for two free exam preparation products of equal value and keep the update service on your original product.
Delivery is instant: your download is sent to your email within one minute of payment, with no limit on how many computers you may install the material on. If nothing arrives within two hours, check your spam folder and contact customer service for help.
What topics are covered in the CISM exam?
The ISACA Certified Information Security Manager exam blueprint is organized into 4 domains. The first three are:
- Information Security Governance — 17% of the exam
- Information Security Program Development and Management — 33% of the exam
- Information Security Incident Management — 30% of the exam
For the complete domain-by-domain breakdown, scroll up to the full exam topics outline above and use it to plan how you distribute your study time.
ISACA Certified Information Security Manager Sample Questions:
Question #1
To optimize the implementation of information security governance in an organization, an information security manager should:
A. Make gradual changes to governance to minimize employee resistance
B. Utilize existing governance structures when possible
C. Implement processes consistent with international standards
D. Ensure change control processes are in place
Question #2
Who is BEST suited to determine how the information in a database should be classified?
A. Database analyst
B. Database administrator (DBA)
C. Information security analyst
D. Data owner
Question #3
Which of the following should be the FIRST step in patch management procedures when receiving an emergency security patch?
A. Validate the authenticity of the patch.
B. Schedule patching based on the criticality.
C. Install the patch immediately to eliminate the vulnerability.
D. Conduct comprehensive testing of the patch.
Question #4
An organization recently activated its business continuity plan (BCP). Employees were notified during the event, but some did not fully follow the communications plan. What is the BEST way to prevent a recurrence?
A. Incentivize employees for following the plan
B. Perform tabletop testing with appropriate employees
C. Update the business impact analysis (BIA)
D. Enhance external communication instructions in the BCP
Question #5
Which of the following is the PRIMARY purpose of an acceptable use policy?
A. To protect the organization from misuse of information assets
B. To facilitate enforcement of security process workflows
C. To provide steps for carrying out security-related procedures
D. To provide minimum security baselines for information assets
Solutions:
| Question #1 Correct Answer: B | Question #2 Correct Answer: D | Question #3 Correct Answer: A | Question #4 Correct Answer: B | Question #5 Correct Answer: A |


PDF Version Demo
1119 Customer Reviews




Quality and ValueGetCertKey Practice Exams are written to the highest standards of technical accuracy, using only certified subject matter experts and published authors for development - no all study materials.
Tested and ApprovedWe are committed to the process of vendor and third party approvals. We believe professionals and executives alike deserve the confidence of quality coverage these authorizations provide.
Easy to PassIf you prepare for the exams using our GetCertKey testing engine, It is easy to succeed for all certifications in the first attempt. You don't have to deal with all dumps or any free torrent / rapidshare all stuff.
Try Before BuyGetCertKey offers free demo of each product. You can check out the interface, question quality and usability of our practice exams before you decide to buy.