CISM — Certified Information Security Manager
CISM is ISACA’s certification for people who manage security programmes rather than operate them. It focuses on governance, risk, programme design and incident management, framed in business rather than technical language. Certification requires five years of information security work experience, of which at least three must be in a management capacity across specified domains.
Last updated: 6 August 2026
The facts
| Vendor | ISACA |
|---|---|
| Level | Management |
| Format | 150 multiple-choice questions in 4 hours, scaled 200–800 with 450 to pass. Delivered at PSI test centres or online-proctored. Four domains: information security governance, information risk management, information security programme development and management, and incident management. |
| Cost | High band. Exam registration is priced in US dollars with a member discount that usually makes ISACA membership worth buying first, and there is an annual certification maintenance fee on top. Official review manuals and question databases cost extra. Verify current exam, membership and maintenance fees with ISACA. |
| Validity / renewal | Three years, with 20 continuing professional education hours required annually and 120 across the cycle, plus an annual maintenance fee. Fall short and the certification can be revoked. |
| Prerequisites | Five years of information security work experience with at least three years of information security management experience across three or more CISM domains, gained within a defined window around the exam date. Certain degrees and credentials can waive up to two years of the general requirement. You may sit the exam first and apply once the experience is complete — candidates have a limited number of years from passing to submit the application. |
Vendors revise prices, formats and eligibility. Always confirm on the vendor's own site before you pay — including against this page.
Is it worth it?
CISM proves you can run a security programme: set policy, quantify risk in business terms, build capability and manage incidents at the organisational level. In India it is heavily favoured for information security manager, risk lead and governance roles in banking, insurance, telecom and large IT services firms, and RBI, SEBI and similar regulatory environments make ISACA credentials familiar to hiring committees.
The downside
It is entirely management-oriented — nothing in it demonstrates technical ability, and a technically strong candidate can find the exam frustrating because the correct answer is usually the governance answer, not the effective one. It is expensive, the experience gate is real, and for anyone not already in or adjacent to management it delivers almost nothing.
Compared to
| Versus | Verdict |
|---|---|
| CISSP | CISSP is broader and slightly more technical across eight domains; CISM is narrower and purely about managing a security programme. If you want architecture and technical leadership, CISSP; if you are already managing security functions and want the governance credential, CISM. |
| CISA | Same vendor, different function. CISA audits controls; CISM builds and runs them. Auditors and assurance professionals take CISA, security managers take CISM, and consultants sometimes hold both. |
| CompTIA Security+ | Not comparable in level. Security+ is an entry credential with no experience requirement; CISM gates on five years including three in management. Security+ starts a career, CISM formalises a management one. |
Where we fit
We do not teach CISM and do not prepare candidates for it. It is a management credential requiring years of documented managerial experience that training cannot substitute for. We do not issue it, we are not an ISACA accredited training organisation, and we do not sell exam registrations. Amit Kumar holds CEH and CRTA, not CISM. If you are early in your career, we will tell you plainly to build hands-on skill first.
We issue no vendor certification and resell no exam vouchers. Buy from the vendor.
CISM — FAQs
What experience does CISM require?
▾
Can I take the CISM exam before I have the experience?
▾
CISM or CISSP for a security manager role in India?
▾
Fresher CISM kar sakta hai kya?
▾
Not sure if CISM is the right next step?
Free call. If the honest answer is a cheaper certification, or six more months of lab work before you pay anyone, that is what you will hear.
Call +91 75175 72000