Certified Information Security Manager

by ISACA CISM

ISACA's CISM validates that you can build and run an enterprise information security program: governance, risk, program development, and incident management. It's the go-to credential for security managers and aspiring CISOs.

1,000+ practice questions4 exam domainsFree trial included

Exam blueprint

Official domain weightings: where the questions come from, and where to spend your study time.

Information Security Governance17%
Information Security Risk Management20%
Information Security Program33%
Incident Management30%
Free trial

Try a real CISM question

Feel the real question style and difficulty. No card required. Then unlock the full 1,000+ question bank, blueprint-aligned by domain, with your readiness score and pass confidence.

Start your free trial

Sample question

The PRIMARY goal of an information security governance program is to:

AAlign the security strategy with business objectives
BEliminate all information security risk
CEnsure the organization passes every audit
DDeploy the latest security technologies

Why: Governance exists to align information security with business goals and support them, not to eliminate all risk or chase tools.