Governance, accountability and culture
Connect board direction, enterprise objectives, decision rights, risk ownership and organizational culture to an information-security mandate.
Prepare for ISACA CISM by connecting enterprise governance, risk ownership, security-program delivery and incident leadership to business-led management decisions across the four-domain outline.
A provider-focused instructor guides the learning plan, explains key objectives, and helps you prepare with confidence.
Meet your instructor →Build from enterprise direction to risk decisions, program delivery and incident leadership. Each unit connects security work to ownership, business impact and evidence that executives can use.
Connect board direction, enterprise objectives, decision rights, risk ownership and organizational culture to an information-security mandate.
Translate business goals, legal obligations and enterprise architecture into a measurable security strategy, roadmap, budget and defensible business case.
Frame scenarios using assets, threats, vulnerabilities, likelihood and business impact; distinguish inherent, residual and emerging risk without relying on false precision.
Choose avoidance, mitigation, transfer or acceptance within risk appetite, assign accountable owners and communicate exposure in language decision-makers can use.
Convert strategy into policies, standards, roles, capabilities, asset classification, control objectives, sourcing decisions and a prioritized delivery roadmap.
Implement and integrate controls, test effectiveness, manage third parties, build awareness and report metrics that distinguish activity from risk reduction.
Align response plans with business impact analysis, continuity and disaster recovery; define classification, authority, communications and realistic exercises.
Direct investigation, containment, notification, eradication and recovery while preserving evidence, coordinating stakeholders and converting lessons into corrective action.
ISACA says the CISM exam remains 150 questions across four domains, with revised weighting taking effect on 3 November 2026.
The domains remain the same. For exams through 2 November 2026, use 17/20/33/30. From 3 November 2026, use 18/20/33/29 and include the refreshed emphasis on security strategy, program development, enterprise architecture and information-security architecture.
Enterprise governance, legal and regulatory context, security strategy, architecture, business cases, roles and executive reporting.
Threat and vulnerability analysis, risk assessment, ownership, treatment, monitoring and decision-ready reporting.
Resources, asset classification, policies, control design and testing, awareness, suppliers, metrics and program communication.
Readiness, business impact, continuity and recovery alignment, classification, investigation, containment, communication and lessons learned.
Weighting note: left value applies through 2 November 2026; right value applies from 3 November 2026. Confirm the outline tied to your appointment before final revision. Read ISACA's 2026 update →
ISACA permits candidates to take the exam before meeting the experience requirement. Certification currently requires five years of information-security management experience across at least three of the four domains, gained within the applicable period.
Use your appointment date to select the current or 3 November 2026 weighting, then practise management decisions across all four domains.
ISACA currently lists continuous registration, PSI test-center or remote-proctored delivery and a six-month eligibility period after registration.
Verify current administration, identification, scheduling, retake and scoring rules in the official candidate guide.
Apply within five years of passing, obtain supervisor verification and pay the currently published US$50 application fee.
ISACA currently requires at least 20 CPE hours annually and 120 over three years, plus maintenance fees and professional obligations.
ISACA currently lists US$575 for members and US$760 for non-members. Taxes, membership and regional checkout can change the final amount.
The timed set covers governance, risk, program and incident management with explanations and an official-outline reference. It is a focused diagnostic, not a reproduction of the 150-question CISM exam.
45-minute timer · four-domain result · explanations · official source
Start CISM diagnostic →BOOKING GUIDEVerify fee and routeConfirm membership, delivery option, exam date, outline version and current ISACA policies before payment.
Open CISM voucher guide →COMPARECISA audit pathwayChoose CISA for audit and assurance; choose CISM for security governance and management.
Compare with CISA →CISM is a trademark of ISACA. ITCertPath is an independent preparation provider and is not affiliated with or endorsed by ISACA. Questions are original learning content, not copied, recalled or live exam items.
Clear answers about curriculum, audience, instructors, fees, and scheduling.
The four domains remain the same. ISACA states that weighting changes from 17/20/33/30 to 18/20/33/29, with refreshed emphasis including security strategy, program development, enterprise architecture and information-security architecture. Use the outline tied to your exam date.
Yes. ISACA states that the exam is open to interested candidates. Certification currently requires five years of professional information-security management experience across at least three of the four domains, plus the other application requirements.
ISACA currently lists US$575 for members and US$760 for non-members. Confirm current membership, taxes, regional checkout and the final amount directly with ISACA before payment.
No. It contains 30 original management scenarios across all four domains with a 45-minute timer and explanations. It is a focused learning diagnostic, not a full 150-question simulation or an official ISACA examination.
CISM focuses on managing security governance, risk, programs and incidents. CISA focuses on information-systems audit and assurance. Choose the path that best matches your responsibilities and target role.
Use this provider-aligned training course to understand the certification, practise with original questions where available, then verify the exact exam voucher, region and validity before booking.
Verified learner reviews will appear here as this course receives feedback.
Online course availability is confirmed by program and cohort. Candidates can review the curriculum globally, then ask for a schedule and contact route matched to their region.
Ask about online course availability across India and local support in Madhapur, Hyderabad.
Contact India team →Ask about U.S. online delivery, Dallas support and online access for New York learners.
Contact USA team →Share your country, certification provider and exact exam code so availability and the correct next step can be checked without implying a local office.
Ask about my country →Certification owners control official exams, eligibility and credentials. ITCertPath provides independent training, original practice and purchasing guidance; availability is confirmed before enrollment or payment.
Speak with ITCertPath about course availability, format, and preparation options.