ISACA CISM Study Guide: Four Security Management Domains and Updated Outline

Prepare for ISACA CISM with the November 3, 2026 outline transition, domain weights, experience requirements, and management-focused study guidance.

ISACA CISM (Certified Information Security Manager) is for professionals responsible for information security governance, risk management, security programs, and incident management. It emphasizes aligning security work with business objectives and delivering it through clear accountability, resources, and measures.

Pay attention to the outline transition: exams through November 2, 2026 use the existing outline and weights. Exams from November 3, 2026 use the updated outline. This guide shows both weight sets. For an exam on or after the change date, use ISACA’s updated study materials. See the official CISM outline and update announcement.

Who is this exam for?

CISM suits information security managers, governance and risk leads, security program owners, consultants, and professionals who design, implement, or oversee security programs. You may take the exam first, but certification still requires the relevant professional experience.

Exam format and certification requirements

The CISM exam has 150 multiple-choice questions and lasts four hours. ISACA reports scores on a 200–800 scale; 450 or higher is passing. After passing, certification generally requires five years of information security management experience across at least three of the four CISM domains. Up to two years of experience waivers may be available under ISACA’s rules. Experience must fall within the permitted period before application and be verified by a supervisor or manager. Apply within five years of passing. Check ISACA’s official certification requirements.

Four exam domains and weights

Domain Before Nov 3, 2026 From Nov 3, 2026 Main topics
1. Information Security Governance 17% 18% Enterprise governance, security strategy, roles, policy, and resources
2. Information Security Risk Management 20% 20% Risk assessment, treatment, ownership, monitoring, and reporting
3. Information Security Program 33% 33% Program development, control design and implementation, people, metrics, and communication
4. Incident Management 30% 29% Readiness, continuity and recovery, investigation, containment, communication, and review

The updated outline keeps the same four domains but adjusts some content and weights. It adds enterprise architecture and information security architecture topics, reflecting the need for managers to understand the technology environment they oversee. Domain 3 has the largest weight, so practice how to build, integrate, and measure a security program.

How to study the four domains

1. Information Security Governance

Understand organizational culture, legal and contractual requirements, governance structures, roles, and responsibilities. Study how to develop a security strategy aligned with business strategy, select governance frameworks, establish policies, and plan budgets and staffing.

Management scenarios often call for leadership support, clear decision rights, and accountability before implementation. Security teams provide risk and business impact information so leaders can decide; priorities should not be set in isolation from the business.

2. Information Security Risk Management

Review the threat landscape, vulnerability and control deficiency analysis, risk assessment, and risk response. Distinguish acceptance, reduction, transfer, and avoidance, as well as risk owners, control owners, monitoring, and reporting.

Escalate risk in light of business impact, organizational risk appetite, and existing controls. A security manager facilitates the process and recommends action; an appropriately authorized business risk owner accepts risk.

3. Information Security Program

Study program development and ongoing management: people and technology resources, asset identification and classification, frameworks, policies, procedures, metrics, and control selection, implementation, testing, and evaluation. Include awareness training, external service management, and program communications.

Updated materials add enterprise architecture and information security architecture topics. Treat architecture as a way to connect business needs with control design: understand processes, system dependencies, and data flows to decide what the program should protect, how it should integrate with IT initiatives, and how to measure outcomes.

4. Incident Management

Readiness includes an incident response plan, business impact analysis, business continuity plan, disaster recovery plan, incident classification, and exercises. Operational response covers investigation, evaluation, containment, notification and escalation, eradication, recovery, and post-incident review.

Incident response should align with continuity and disaster recovery. Managers ensure teams have clear responsibilities, tools, and communication channels, then use exercises to find gaps. During an incident, control impact, meet notification duties, preserve records, and follow with root-cause analysis and corrective action.

Concepts that are easy to confuse

  • Security strategy and security program: Strategy sets direction and objectives; the program turns them into people, processes, controls, and measures.
  • Risk owner and control owner: The risk owner makes risk decisions; the control owner designs or operates a specific control.
  • Risk treatment and monitoring: Treatment chooses a response; monitoring tracks how risk and controls change.
  • Incident response and business continuity: Incident response handles the security event; continuity sustains critical operations, while disaster recovery restores systems.
  • Control deployment and effectiveness: A deployed control is not necessarily effective; testing, evaluation, and improvement are still needed.

Six-week study plan

Week Focus Suggested outcome
1 Governance, strategy, roles, and policy Connect security decisions to business goals and authority
2 Risk assessment, response, ownership, and monitoring Choose an appropriate treatment and escalation path
3 Program development, frameworks, assets, and policy Explain how to build a security program from strategy
4 Control selection, implementation, testing, metrics, and vendors Evaluate control and program effectiveness, not just deployment
5 Incident readiness, response, continuity, and recovery Distinguish plans and explain management actions in order
6 Choose materials for the exam date and practice integrated scenarios Analyze ownership, risk, and business impact across domains

Choose your study materials after confirming your exam date and applicable outline. When reviewing missed questions, ask who has decision authority, which business objective is affected, what evidence or metric is needed, and what the best management action is.

Exam readiness checklist

  • Confirm whether your exam date falls before or after the November 3, 2026 outline change.
  • Explain the four domains and the weights for the applicable version.
  • Distinguish strategy, program delivery, risk treatment, and control operations.
  • Connect risk to business impact, appetite, and authorized decisions.
  • Coordinate incident response with business continuity and disaster recovery.
  • Verify waiver eligibility, application deadlines, and evidence requirements.

What to practice next

CISM scenarios often ask for the best next step from a management perspective. Identify business goals, risk ownership, and authority first, then select an action that helps governance or the program work effectively. Start CISM practice

WeChat mini program

IT知习 mini program QR code

Search WeChat for: IT知习