ISACA CISM - Certified Information Security Manager
- Exam Code: CISM
- Exam Name: Certified Information Security Manager
- Updated: Sep 23, 2026
- Q & A: 1193 Questions and Answers
Good materials should feel easy from the first click. TestPDF built its CISM question bank for clarity — main points that are easy to acquire, content that reads cleanly, and a free demo so you can confirm the ISACA Certified Information Security Manager quality before paying.
| Certification Vendor: | ISACA |
|---|---|
| Exam Name: | Certified Information Security Manager |
| Exam Number: | CISM |
| Real Exam Qty: | 150 |
| Certificate Validity Period: | 3 years (requires maintenance fees and CPE) |
| Exam Format: | Multiple Choice |
| Available Languages: | English, Chinese-Simplified, French, German, Spanish, Japanese |
| Related Certifications: | CISM |
| Passing Score: | 450 (out of 800) |
| Exam Duration: | 240 minutes |
| Exam Price: | $575 (Member) / $760 (Non-Member) |
| Sample Questions: | ![]() |
| Exam Way: | Computer-based testing at authorized PSI testing centers or remotely proctored. |
| Pre Condition: | To earn the CISM certification, candidates must pass the exam and possess a minimum of five years of information security work experience with a minimum of three years of information security management work experience in three or more of the CISM domains. Substitutions and waivers for general information security experience are available. |
| Official Syllabus URL: | https://www.isaca.org/credentialing/cism |
| Section | Weight | Objectives |
|---|---|---|
| Information Security Governance | 17% | - Establish and/or maintain an information security governance framework and supporting processes to ensure that the information security strategy is aligned with the goals and objectives of the organization - Establish and/or maintain information security policies to guide the development of standards, procedures and guidelines in alignment with enterprise goals and objectives - Define and communicate the roles and responsibilities for information security throughout the organization - Identify internal and external influences to the organization that affect the information security strategy and program - Obtain commitment from senior management and other stakeholders for the information security program - Establish, monitor, evaluate and report information security management metrics - Develop business cases to support investments in information security |
| Information Security Incident Management | 30% | - Develop and implement processes to ensure the timely identification of information security incidents - Establish and maintain incident escalation and notification processes - Establish and maintain processes to investigate and document information security incidents - Organize, train and equip teams to effectively respond to information security incidents - Establish and maintain an incident response plan to ensure an effective and timely response to information security incidents - Establish and maintain communication plans and processes to manage communication with internal and external entities - Establish and maintain an organizational definition of, and severity hierarchy for, information security incidents - Test, review and revise the incident response plan |
| Information Security Program Development and Management | 33% | - Align the information security program with the operational objectives of other business functions - Develop and maintain a security awareness, training and education program for all stakeholders - Integrate information security requirements into organizational processes - Establish and maintain information security architectures (people, process, technology) - Establish, communicate and maintain organizational information security standards, guidelines, procedures and other documentation - Monitor and manage the information security program - Establish and/or maintain the information security program in alignment with the information security strategy - Identify, acquire and manage information security requirements for internal and external resources (services, partners, and suppliers) |
| Information Security Risk Management | 20% | - Determine appropriate risk treatment options - Integrate risk management into business and IT processes - Establish and/or maintain a process for information asset identification, classification, risk assessment and ownership - Identify legal, regulatory, organizational and other applicable compliance requirements - Ensure that risk assessments, vulnerability assessments and threat assessments are performed consistently, at appropriate times, and to identify acceptable risk - Monitor and communicate the information security risk posture - Evaluate information security controls to determine whether they are appropriate and effectively mitigate risk - Identify and/or recommend risk treatment options |
Immediately and easily. Upon successful payment, our system sends the product file to your mailbox automatically — typically within about a minute — with an instant download link as well. If nothing arrives within two hours, check your spam folder and contact support. Installations are unlimited, the PDF supports printing for paper-based review, and your purchase includes 365 days of free updates: whenever the exam content changes, the latest version reaches you automatically, with a 50% renewal discount after the year ends.
The ISACA Certified Information Security Manager blueprint covers these principal domains:
The remaining domains appear in the full official outline, all of which our bank addresses.
As of the latest information, the passing score for the CISM exam is 450 (out of 800) and the fee is $575 (Member) / $760 (Non-Member). ISACA can revise both, so confirm the current figures on the official site before registering.
Documented and dependable. If you fail the corresponding exam within 60 days of purchase, email us a scanned copy of your enrollment slip and your official Score Report PDF within two days of the exam date; verified claims are refunded in full within seven days. Exclusions apply: exams taken within three days of purchase, candidate names that do not match the payer, and free or expired products. Alternatively, request a free exchange for two products of equal value.
ISACA lists the following prerequisites for the ISACA Certified Information Security Manager: To earn the CISM certification, candidates must pass the exam and possess a minimum of five years of information security work experience with a minimum of three years of information security management work experience in three or more of the CISM domains. Substitutions and waivers for general information security experience are available..
Confirm the details on the official certification page before you book.
Per current exam information, the CISM exam includes 150 questions and allows 240 minutes minutes. Timed practice beforehand makes the format feel routine on the day.
Because every step respects your time. Buying is a simple, transparent procedure: choose your version or package, see the cost generated automatically, confirm, and order — then the materials arrive by email in about a minute. The CISM content is clear, the main points easy to acquire, and every answer expert-verified; the PDF prints for paper review. When the exam changes, our experts devote their energy to immediate research and revision, and critical comments trigger improvement measures as soon as possible. A free demo lets you run a mini-test and confirm quality first, and your personal information is protected on an integrity-based platform throughout.
Labeling information according to its security classification:
Correct Answer: D 🗳️
Explanation: Only visible for TestPDF members. You can sign-up / login (it's free).
Which of the following processes is MOST important for the success of a business continuity plan?
Correct Answer: C 🗳️
Explanation: Only visible for TestPDF members. You can sign-up / login (it's free).
Which of the following should be given the HIGHEST priority during an information security post-incident review?
Correct Answer: A 🗳️
Explanation: Only visible for TestPDF members. You can sign-up / login (it's free).
Which of the following is MOST difficult to measure following an information security breach?
Correct Answer: A 🗳️
Explanation: Only visible for TestPDF members. You can sign-up / login (it's free).
Which of the following is the PRIMARY objective of information asset classification?
Correct Answer: C 🗳️
Explanation: Only visible for TestPDF members. You can sign-up / login (it's free).
Over 40257+ Satisfied Customers
988 Customer ReviewsCustomers Feedback (* Some similar or old comments have been hidden.)The CISM exam braindumps have updated to the latest. But no one had tested the validity, i was willing to have a try and i passed the exam in the end. Yes, they are valid and you can pass for sure if you buy them.
The CISM exam materials are really updated fast. I received the updated version form time to time for i had no time to attend it until today i wrote it and passed. Thank you for being so excellent!
I recently purchased CISM exam dumps from TestPDF and passed the exam sucessfully with good score. Next time I still choose to use your dumps. Thanks so much!
I passed the CISM exam and learned a lot of important knowledge to solve problems in my work. Thanks for your helpful exam materials!
Thanks TestPDF for helping me clear CISM exam.
My friend introduces this website to me. Yeh, very good. The service is very very good. Thanks to the dumps
Pdf exam guide for CISM specialist exam are very similar to the original exam. I passed my exam with 97% marks.
After I studied 3 days on the CISM premium pdf dumps. All the questions in the exam were from this CISM dumps. Passed exam surely.
Thanks TestPDF CISM real exam questions.
This is really an authentic study flatform to offering the best CISM exam questions. I have passed my CISM exam with its help. So lucky to find it!
Thanks to TestPDF today I am a proud CISM certified professional
Always Incredible!
I am your old customers and recently just passed my CISM exam.
I have passed the CISM exam yesterday with a great score .Thanks a lot for CISM dumps and good luck for every body!
If you want to pass your CISM exam just one time, you can choose TestPDF, since I passed my CISM exam with the help of TestPDF.
I have passed CISM exam.
TestPDF Practice Exams are written to the highest standards of technical accuracy, using only certified subject matter experts and published authors for development - no all study materials.
We are committed to the process of vendor and third party approvals. We believe professionals and executives alike deserve the confidence of quality coverage these authorizations provide.
If you prepare for the exams using our TestPDF testing engine, It is easy to succeed for all certifications in the first attempt. You don't have to deal with all dumps or any free torrent / rapidshare all stuff.
TestPDF offers free demo of each product. You can check out the interface, question quality and usability of our practice exams before you decide to buy.