Cyber Defence
ISACA · Management · 150 multiple-choice questions in 4 hours, scaled 200–800 with 450 to pass. Delivered at PSI test centres or online-proctored. Four domains: information security governance, information risk management, information security programme development and management, and incident management.

CISM — Certified Information Security Manager

CISM is ISACA’s certification for people who manage security programmes rather than operate them. It focuses on governance, risk, programme design and incident management, framed in business rather than technical language. Certification requires five years of information security work experience, of which at least three must be in a management capacity across specified domains.

Last updated: 6 August 2026

The facts

VendorISACA
LevelManagement
Format150 multiple-choice questions in 4 hours, scaled 200–800 with 450 to pass. Delivered at PSI test centres or online-proctored. Four domains: information security governance, information risk management, information security programme development and management, and incident management.
CostHigh band. Exam registration is priced in US dollars with a member discount that usually makes ISACA membership worth buying first, and there is an annual certification maintenance fee on top. Official review manuals and question databases cost extra. Verify current exam, membership and maintenance fees with ISACA.
Validity / renewalThree years, with 20 continuing professional education hours required annually and 120 across the cycle, plus an annual maintenance fee. Fall short and the certification can be revoked.
PrerequisitesFive years of information security work experience with at least three years of information security management experience across three or more CISM domains, gained within a defined window around the exam date. Certain degrees and credentials can waive up to two years of the general requirement. You may sit the exam first and apply once the experience is complete — candidates have a limited number of years from passing to submit the application.

Vendors revise prices, formats and eligibility. Always confirm on the vendor's own site before you pay — including against this page.

Is it worth it?

CISM proves you can run a security programme: set policy, quantify risk in business terms, build capability and manage incidents at the organisational level. In India it is heavily favoured for information security manager, risk lead and governance roles in banking, insurance, telecom and large IT services firms, and RBI, SEBI and similar regulatory environments make ISACA credentials familiar to hiring committees.

The downside

It is entirely management-oriented — nothing in it demonstrates technical ability, and a technically strong candidate can find the exam frustrating because the correct answer is usually the governance answer, not the effective one. It is expensive, the experience gate is real, and for anyone not already in or adjacent to management it delivers almost nothing.

Compared to

VersusVerdict
CISSPCISSP is broader and slightly more technical across eight domains; CISM is narrower and purely about managing a security programme. If you want architecture and technical leadership, CISSP; if you are already managing security functions and want the governance credential, CISM.
CISASame vendor, different function. CISA audits controls; CISM builds and runs them. Auditors and assurance professionals take CISA, security managers take CISM, and consultants sometimes hold both.
CompTIA Security+Not comparable in level. Security+ is an entry credential with no experience requirement; CISM gates on five years including three in management. Security+ starts a career, CISM formalises a management one.

Where we fit

We do not teach CISM and do not prepare candidates for it. It is a management credential requiring years of documented managerial experience that training cannot substitute for. We do not issue it, we are not an ISACA accredited training organisation, and we do not sell exam registrations. Amit Kumar holds CEH and CRTA, not CISM. If you are early in your career, we will tell you plainly to build hands-on skill first.

We issue no vendor certification and resell no exam vouchers. Buy from the vendor.

CISM — FAQs

What experience does CISM require?

Five years of information security work experience, including at least three years of security management experience spread across three or more CISM domains, earned within ISACA’s defined window relative to your exam date. Some degrees and credentials can waive up to two years of the general requirement, but not the management portion.

Can I take the CISM exam before I have the experience?

Yes. You can sit and pass the exam first, then apply for certification once you meet the experience requirement. ISACA allows a limited number of years between passing and applying, so do not pass it a decade early.

CISM or CISSP for a security manager role in India?

Both appear in Indian job specifications. CISM is favoured in banking, insurance and regulated financial environments where ISACA credentials are already familiar; CISSP is more common in IT services, product companies and global capability centres. Check the actual job listings in your target sector rather than the general internet debate.

Fresher CISM kar sakta hai kya?

Exam de sakta hai, par certificate nahi milega — paanch saal ka experience chahiye jismein teen saal management ka ho. Fresher ke liye ye paisa aur time dono ki barbaadi hai. Pehle skill aur job, phir kuch saal baad CISM ka sochna sahi rahega.

Not sure if CISM is the right next step?

Free call. If the honest answer is a cheaper certification, or six more months of lab work before you pay anyone, that is what you will hear.

Call +91 75175 72000