CISM (Certified Information Security Manager) Explained

Learnsignal Education Team
Updated

CISM (Certified Information Security Manager), also awarded by ISACA, is the management-track counterpart to CISA — another certification Learnsignal's existing cybersecurity certifications roundup only mentions in a comparison table, without the exam structure or career detail a candidate actually needs.

What CISM is and who it's for

Where CISA focuses on auditing and assuring information systems, CISM is aimed at people who actually manage an organisation's information security programme — a leadership and governance-oriented credential rather than a hands-on technical one. ISACA positions it for information security managers, aspiring CISOs, and IT risk professionals responsible for aligning security strategy with business objectives, rather than for security engineers or analysts doing day-to-day technical work.

Exam structure

The CISM exam is 150 questions delivered over four hours, scored on ISACA's scaled 200–800 system with 450 needed to pass — the same format and scoring model used for CISA. The exam is built around four domains: Information Security Governance, Information Security Risk Management, Information Security Program, and Incident Management, with ISACA updating the domain weightings and content outline effective November 2026, so candidates sitting the exam close to that date should check they're studying the current version. Under the outline in effect through 2026, Information Security Program and Incident Management together account for the majority of exam content, reflecting how much of the role is about running a functioning security programme and responding effectively when things go wrong, rather than pure policy-writing.

Eligibility and experience requirement

Like CISA, CISM requires five years of relevant professional experience — specifically in information security management — before certification is awarded, although a portion of that can typically be satisfied through related certifications or a relevant academic background, similar to CISA's substitution rules. As with CISA, candidates can sit and pass the exam before completing the experience requirement, then apply for certification once it's satisfied.

How CISM complements ACCA and CIMA

Information security governance and risk sit almost entirely outside the ACCA and CIMA syllabi, which touch on general business risk and controls but not the specifics of running a security programme. For finance professionals moving into risk, governance, or technology leadership roles — particularly anyone heading toward a CISO-adjacent or IT risk director path — CISM is one of the few credentials that speaks directly to that management responsibility, in a way a general accounting or even a general IT certification doesn't.

Career paths

CISM holders typically progress into roles such as Information Security Manager, IT Risk Manager, Director of Information Security, or eventually Chief Information Security Officer. It's increasingly requested alongside, or instead of, CISSP for roles that are more about governance and strategic risk management than hands-on technical security operations. Larger organisations increasingly expect a security leader to hold a recognised management-level credential like CISM specifically, rather than treating a technical certification like CISSP as an automatic substitute — the two test genuinely different competencies, and hiring panels for governance-heavy roles have grown more precise about which one they're actually looking for.

Domain weightings in more detail

Under the exam content outline in effect through 2026, the four domains are weighted roughly as follows: Information Security Governance around 17%, Information Security Risk Management around 20%, Information Security Program around 33%, and Incident Management around 30%. That weighting reflects a shift ISACA has made in recent years toward incident response and operational programme management, and away from a heavier weighting on pure governance theory — a sign that the exam, and the role it certifies, increasingly expects candidates to have handled real security incidents rather than just written policy documents.

Maintaining the certification

Like CISA, CISM certification isn't a one-time achievement — ISACA requires ongoing continuing professional education (CPE) hours to maintain it, tracked and reported annually. For accountants who already hold ACCA or CIMA membership, this will feel familiar, since it mirrors the CPD obligations both bodies already require, just tracked through a separate ISACA portal rather than through the accounting body itself.

FAQs

Is CISM harder than CISA?
They're comparable in exam difficulty and share the same format, but they test different things — CISM leans more heavily on governance, strategy, and risk-management judgement calls, while CISA is more focused on audit methodology and controls testing. Which one is "harder" tends to depend on a candidate's existing background. Candidates who've already sat professional accounting exams like ACCA's Strategic Professional papers often find CISM's scenario-based, judgement-driven questions more familiar in style than CISA's more procedural, controls-focused questions.

Can I hold both CISA and CISM?
Yes, and a meaningful number of senior IT audit and risk professionals do, since the two credentials cover complementary perspectives — independent assurance versus operational security management — on the same underlying subject matter.

Do I need a technical cybersecurity background to pursue CISM?
Not necessarily a hands-on technical background, but you do need the five years of professional experience in information security management specifically, so most candidates come from security, IT risk, or IT governance roles already.

This page was last updated:

Learnsignal Education Team

Expert Tutor at Learnsignal

Qualified professional with years of experience helping students advance their professional careers.

View all posts by Learnsignal Education Team

Subscribe to Our Newsletter

Join over 30,000+ Learnsignal students and get regular insights delivered to your inbox.

Ready to Start Your Qualification Guides Journey?

Join thousands of successful students who have achieved their qualifications with Learnsignal.

Ready to get started?

Join 100,000+ students across 130 countries. Choose a plan that fits your goals — cancel anytime.

View plans