If you are moving from hands-on security work into leading a security program, the ISACA Certified Information Security Manager (CISM)® is one of the most recognized ways to prove you are ready. The exam asks you to think like a manager, not a technician, and that shift can make even experienced security pros nervous. The good news is that ISACA publishes exactly what it tests, and a study plan built on that blueprint can get you across the finish line on your first try.

In this guide, we’ll walk you through the exam format, the updated CISM content outline that takes effect November 3, 2026, what changed from the previous version, the official resources worth using, and the questions candidates ask most.

What Is the ISACA CISM Exam?

The CISM is ISACA’s credential for professionals who design, build, and manage an enterprise information security program. According to ISACA, more than 111,000 professionals have earned it since it launched in 2002.

Where many security certifications focus on configuring controls, CISM focuses on governance, risk, program management, and incident management from the point of view of the person accountable to senior leadership.

That perspective drives the questions. Most items describe a business situation and ask what the information security manager should do first, best, or most effectively. The correct answer usually aligns security with business objectives and follows a defined process, rather than jumping to a technical fix.

What Is the CISM Exam Format?

Here is the exam at a glance, based on the ISACA Exam Candidate Guide (2026) and the CISM certification page. ISACA’s announcement of the 2026 update doesn’t mention any change to the exam format.

  • Questions: 150 multiple-choice questions, each with a stem and four answer options.
  • Scored vs. unscored: The exam includes unscored pretest items along with scored items. ISACA doesn’t say how many are pretest, so treat every question as if it counts.
  • Time: 4 hours (240 minutes). Breaks are allowed with proctor permission, but the clock keeps running.
  • Delivery: Computer-based at a PSI testing center or through online remote proctoring. Registration is continuous, and testing is year-round.
  • Scoring: Scaled scores range from 200 to 800. You need a score of 450 or higher to pass.
  • Results: A preliminary pass/fail result appears on screen when you finish, and your official score arrives within 10 working days.

With 240 minutes for 150 questions, you have about 96 seconds per question. The scenarios are wordy, so practice reading for the key qualifier.

Which CISM Content Outline Applies to Your Exam?

ISACA announced in September 2026 that it has updated the CISM exam content outline. Your test date, not your registration date, decides which version you’ll see:

  • Exams taken through November 2, 2026: The previous outline (in place since June 2022) applies. Its weights are 17%, 20%, 33%, and 30%.
  • Exams taken on or after November 3, 2026: The updated outline applies, with the weights shown below.

Registration gives you a six-month testing window, so you can register under one outline and sit under the other. ISACA’s press release on the update strongly recommends that anyone testing on or after November 3, 2026, use the updated CISM prep materials, which ISACA released on September 1, 2026.

What Changed in the 2026 CISM Outline?

The update is an evolution, not a rebuild. Here’s what ISACA says changed:

  • Same four domains: The domain names are unchanged.
  • Small weight shifts: Governance rises from 17% to 18%, and Incident Management drops from 30% to 29%. Risk Management (20%) and Information Security Program (33%) stay the same.
  • Two new content areas: Enterprise architecture and information security architecture, reflecting the need for security managers to understand the technologies they’re responsible for.
  • More emphasis on information security strategy and program development, with some content redistributed across domains.

What Is on the CISM Exam? The Four Domains

Here is how the 150 questions break down under the updated outline. The approximate question counts are calculated from ISACA’s percentages.

  • Domain 1, Information Security Governance: 18% (about 27 questions)
  • Domain 2, Information Security Risk Management: 20% (about 30 questions)
  • Domain 3, Information Security Program: 33% (about 50 questions)
  • Domain 4, Incident Management: 29% (about 43 questions)

The topic bullets below come from the subtopics in ISACA’s published outline. Because the 2026 update keeps the same domains and mostly redistributes content, they remain a reliable map, but check the CISM Exam Content Outline for the updated wording.

Domain 1: Information Security Governance (18%)

Governance is about direction and accountability. This domain covers how the security strategy connects to business goals, how security fits into corporate governance, and who is responsible for what. It has two parts: Enterprise Governance and Information Security Strategy.

  • Organizational culture and its effect on security.
  • Legal, regulatory, and contractual requirements.
  • Organizational structures, roles, and responsibilities.
  • Developing the information security strategy, using governance frameworks and standards.
  • Strategic planning, including budgets, resources, and business cases.

What questions look like: A new CISO finds that security policies exist but aren’t followed. The best first step is usually to understand business objectives and gain senior management support, not to rewrite the policies or buy a tool. With strategy getting more emphasis in 2026, expect this kind of question often.

Domain 2: Information Security Risk Management (20%)

This domain covers how you identify, assess, and respond to information risk so it stays within the organization’s risk appetite. It has two parts: Information Security Risk Assessment and Information Security Risk Response.

  • The emerging risk and threat landscape.
  • Vulnerability and control deficiency analysis.
  • Risk assessment and analysis.
  • Risk treatment and response options (mitigate, transfer, avoid, accept).
  • Risk and control ownership, plus risk monitoring and reporting.

Study tip: Know who owns what. Business risk owners accept risk; the security manager advises and reports. Many wrong answers have the security manager making a decision that belongs to the business.

Domain 3: Information Security Program (33%)

The largest domain covers turning strategy into a working program. It includes Information Security Program Development and Information Security Program Management.

  • Program resources, industry standards, and frameworks.
  • Information asset identification and classification.
  • Policies, procedures, and guidelines, plus program metrics.
  • Control design, selection, implementation, testing, and evaluation.
  • Awareness and training, management of external services, and program reporting.

Study tip: Learn the hierarchy of policy, standard, procedure, and guideline, and know which metrics matter to executives (business-relevant, trend-based) versus operations (technical counts).

Domain 4: Incident Management (29%)

This domain covers preparing for and handling security incidents. Its parts are Incident Management Readiness and Incident Management Operations.

  • The incident response plan, business impact analysis (BIA), business continuity plan (BCP), and disaster recovery plan (DRP).
  • Incident classification and categorization.
  • Training, testing, and evaluation of plans.
  • Tools, investigation, containment, and response communications.
  • Eradication, recovery, and post-incident review.

What questions look like: During an active incident, the best answer is usually to follow the incident response plan, escalate per the communication plan, and preserve evidence before wiping systems.

New in 2026: Enterprise and Information Security Architecture

ISACA added these areas because security managers need to understand the technology they’re accountable for. You won’t design networks, but know how enterprise architecture describes the business’s processes, data, applications, and technology, and how security architecture builds security principles and controls into that structure rather than bolting them on later. Think about how architecture decisions support the strategy (Domain 1), reveal assets and dependencies for risk assessment (Domain 2), and shape control design (Domain 3).

How Should You Use the CISM Blueprint to Build a Study Plan?

Domains 3 and 4 together make up 62% of the updated exam, so they deserve the most study time. Just don’t skip governance and risk. Those domains teach the “manager’s mindset” that decides many questions in the other two.

  1. Confirm your outline: Check whether your exam falls before or on/after November 3, 2026.
  2. Take a mixed baseline: Answer a set of questions across all four domains before you start reviewing.
  3. Map every miss: Tag each wrong answer to a domain and subtopic so patterns show up.
  4. Weight your time: Focus on weak areas in the heavy domains first while keeping all four in rotation, and add time for architecture and strategy.
  5. Review the “why”: For each miss, write one sentence on why the correct answer is more managerial or better aligned with the business.

What Official CISM Resources Should You Use?

Commonly used references:

  • CISM Review Manual, 16th Edition (ISBN 978-1604209013)
  • CISM Certified Information Security Manager All-in-One Exam Guide, 2nd Edition (ISBN 978-1264268313)

Frequently Asked Questions About the CISM Exam

What is the passing score for the CISM exam?
You need a scaled score of 450 on a 200 to 800 scale. The scaled score is not a percentage, so there’s no fixed number of questions you must answer correctly.

How much does the CISM exam cost?
ISACA lists the exam at US$575 for members and US$760 for non-members. After you pass, there’s a US$50 application processing fee for certification.

How soon will I get my results?
You see a preliminary result on screen right away. The official score arrives within 10 working days.

What if I don’t pass?
ISACA allows four attempts in a rolling 12-month period. You must wait 30 days after your first attempt, then 90 days before your third and fourth. Each attempt requires the full registration fee.

Did the CISM outline change?
Yes. An updated outline applies to exams on or after November 3, 2026. The four domains stay the same, Governance moves to 18% and Incident Management to 29%, and enterprise and information security architecture are new content areas.

Do I need five years of experience to take the exam?
No. You can sit for the exam first. You need the experience to become certified, and you have five years from passing to apply.

Start Preparing for the CISM Exam With Pocket Prep

Pocket Prep’s ISACA CISM practice questions give you 1,000 exam-style questions across all four domains, each with a detailed explanation, plus a full-length 150-question mock exam to rehearse for exam day. Use Weakest Subject and Build Your Own Quiz to put your hours where the blueprint says they count. You’ve got this, one question at a time.