Datasheet | ISACA CISM – Security Governance & Risk Leadership | Check Point Software
Datasheet | ISACA CISM – Security Governance & Risk Leadership
Certified Information Security Manager® (CISM®) is ISACA’s information security management certification. It affirms the ability to assess risks, implement effective governance, and proactively respond to incidents—with a strong focus on aligning information security strategy and programs to business goals.
Recommended For
- Information security professionals who design, lead, or manage enterprise information security programs and processes.
- Security and risk stakeholders responsible for governance, risk management, program oversight, and incident management capabilities.
- Professionals preparing for the CISM exam who want an ISACA-aligned, management-focused learning path.
Key Features
- Exam-aligned curriculum mapped to the four CISM job practice domains: Information Security Governance, Information Security Risk Management, Information Security Program, and Incident Management.
- Exam format: 150 multiple-choice questions administered as a computer-based exam at authorized PSI testing centers globally or via remote proctoring.
- Domain weighting (per ISACA exam content outline): Domain 1 (17%), Domain 2 (20%), Domain 3 (33%), Domain 4 (30%).
- Official preparation ecosystem includes ISACA’s CISM Online Review Course, CISM Review Manual, and the CISM Questions, Answers & Explanations Database (12-month subscription; 1,047-question pool).
- Exam content notice: ISACA states the CISM Exam Content Outline will be updated effective 3 November 2026; the CISM exam will reflect the new outline starting that date.
Outcomes & Impact
- Strengthen the ability to govern information security as a business enabler and communicate program value to stakeholders.
- Improve capability to identify and manage information security risk in line with organizational objectives and risk appetite.
- Advance readiness to lead incident management practices that minimize business impact and support recovery.
- Support long-term professional development through ISACA’s continuing education model (minimum 20 CPE hours annually and 120 CPE hours over a 3-year reporting period).
Prerequisites
- Exam eligibility: The CISM exam is open to anyone who has an interest in information security.
- Certification eligibility (after passing): Demonstrate a minimum of five (5) years of professional information security management work experience within the CISM job practice areas, gained within the 10-year period preceding the application date, and apply for certification within five years of passing.
- Experience waivers/substitutions (optional): ISACA allows substitutions for up to two years of general information security work experience based on qualifying credentials or education (as defined by ISACA).
Purchase & Redemption Options
Training is available via:
- Flex Credits.
- Check Point COOP funds.
- Credit Card.