CISM certification exam
Computer-based professional knowledge assessment
- Type
- Written
- Delivery
- Both
Passing score: 450 ISACA scaled score
Exam sections
Information Security Governance
The “Information Security Governance” objective treats objectives, assigned accountability, risk significance, fitness of supporting information, sequence of action, and well-founded conclusions as an end-to-end responsibility. Preparation is successful when the candidate can assign the decision to the correct role, evaluate the available support, and respond at the proper point in the case. It leads into “Information Security Risk Management” in the published outline.
Question notes
When a scenario reaches “Information Security Governance,” remember that the scenario can hinge on professional role, order of action, evidence quality, or stakeholder accountability. Check specifically for this failure condition: insufficient evidence, confused responsibility, premature judgment, or a response aimed at the visible symptom rather than the underlying risk. Judge completion through an auditable connection between purpose and risk, evidence, judgment, conclusion, and stakeholder communication. Published metadata supports study prioritization but does not reveal assessment inventory.
Preparation tips
Keep a short decision journal for “Information Security Governance.” Complete this exercise: Write a short case, identify the responsible role and evidence needed, compare plausible responses, and justify which action comes first. Record whether you detected or prevented unverified inputs, unclear responsibility, judgment before analysis is complete, or a response disconnected from the actual exposure. Attach a documented link from objective into risk, evidence, judgment, conclusion, and stakeholder communication. Ask how a practitioner beginning the next area would interpret the result in “Information Security Risk Management”.
Information Security Risk Management
At the center of “Information Security Risk Management” is objectives, decision ownership, risk significance, reliability of support, sequence of action, and well-founded conclusions. Within the assessment, this becomes a requirement to recognize the responsible party, judge what evidence is still missing, and select the defensible next response. In the published sequence, it follows “Information Security Governance” and precedes “Information Security Program”.
Question notes
Knowing the heading “Information Security Risk Management” is not sufficient; question context may require separating management ownership from independent assurance responsibility. The principal risk is evidence that cannot sustain the claim, misplaced ownership, early conclusions, or an intervention focused on what is visible instead of the risk driving the case. The response should be supported by a clear path from objective through risk, evidence, judgment, conclusion, and stakeholder communication. Use the stored weighting for relative study priority; it does not reveal how many questions will appear.
Preparation tips
Make preparation for “Information Security Risk Management” observable. Practical exercise: Review a flawed conclusion, identify the missing or unreliable evidence, and rewrite it so the final judgment is supportable. Ask a reviewer to test for insufficient evidence, confused responsibility, premature judgment, or corrective work that addresses an effect but not the actual exposure. Give the reviewer a clear path from objective through risk, evidence, judgment, conclusion, and stakeholder communication. Inspect whether the response changes the available options in “Information Security Program”.
Information Security Program
The role of “Information Security Program” in CISM — Certified Information Security Manager is to assess identity context, inherited policy, enforcement boundaries, and observed authorization behavior under realistic production conditions. Knowing the available features is only a starting point; candidates must reason from the security objective into minimum necessary access, responsibility, and control enforcement, and inspectable access results. In the published sequence, it follows “Information Security Risk Management” and precedes “Incident Management”.
Question notes
When a scenario reaches “Information Security Program,” remember that evidence, risk significance, and sequence often distinguish the strongest answer from a partial one. Check specifically for this failure condition: an outwardly valid configuration that exceeds least privilege or leaves exceptional behavior unverified. Judge completion through a permitted case, a denied case, policy-evaluation details and an inspectable activity trail. Section metadata carries the published emphasis; assessment composition can still vary within that boundary.
Preparation tips
After the normal “Information Security Program” path works, continue with an exception. Exercise: Start from least privilege, add only the access required by the scenario, and verify both expected access and expected denial. Failure condition to introduce: an ostensibly valid configuration that exceeds least privilege or leaves exceptional behavior unverified. Compare both attempts using a permitted case, a negative access case, evidence of policy processing, and a traceable security record. Finish with a handoff checklist for “Incident Management”.
Incident Management
The “Incident Management” objective treats visible symptoms, baseline observations, narrowing of possible causes, a targeted fix, and confirmation that service recovered as part of a wider professional sequence. The practical expectation is to reason from baseline and symptoms before changing the affected system, then verify that the reported failure is gone. It draws on work established in “Information Security Program”.
Question notes
For “Incident Management,” the assessment context matters: question context may require separating management ownership from independent assurance responsibility. Failure mode to test: combining changes before isolating cause, overlooking normal behavior, selecting a cause too early, or accepting recovery without evidence. Verification should include recorded metrics, event data, and checks, a hypothesis trail, and post-change validation. Official numeric emphasis is preserved outside the prose, with no estimate of how many items may represent it.
Preparation tips
Turn “Incident Management” into a reviewable practice artifact. Exercise: Investigate a realistic alert, separate root cause from secondary symptoms, and document why the recovery check is sufficient. Challenge condition: changing several variables together, working without a baseline, assuming a correlated event is causal, or failing to validate the correction. Completion evidence: baseline measures, diagnostic records, and tests, a hypothesis trail, and post-change validation. Include a case in which an error from “Information Security Program” reaches this topic.
