This guide covers all key domains and objectives for the CISM certification, focusing on information security governance, risk management, program development, and incident management.
This guide works best as a loop: read a chapter, test yourself with practice questions, look up unfamiliar terms in the glossary, then move to the next chapter.
17 chapters covering every exam objective. Each chapter includes key concepts, exam tips, common traps, comparison tables, and a 5-question quiz at the end.
Start Chapter 1Free timed and untimed practice with instant feedback and full explanations. Pick 10–120 questions per session. Filter by domain to drill your weak areas.
Go to practice testEvery CISMterm defined and searchable. Use it when a chapter mentions a concept you haven't seen before or want a quick refresher on.
Browse glossaryExam blueprint, domain weights, passing score, duration, cost, and registration links. Start here if you're new to this certification.
View exam guideIntroduction to Information Security Governance
Objective 1.1 · Establish and maintain an information security governance framework
Strategic Alignment and Security Strategy Development
Objective 1.2 · Align information security strategy with business goals and objectives
Governance Roles, Responsibilities, and Reporting
Objective 1.3 · Define and communicate information security roles and responsibilities
Governance Metrics, Monitoring, and Reporting
Objective 1.4 · Establish and maintain information security metrics and reporting
Information Risk Management Concepts and Frameworks
Objective 2.1 · Establish and maintain a process for information risk management
Risk Assessment Methodologies and Analysis
Objective 2.2 · Identify and analyze information security risks using established methodologies
Risk Treatment, Response, and Mitigation
Objective 2.3 · Select and implement appropriate risk treatment and response strategies
Risk Monitoring, Reporting, and Communication
Objective 2.4 · Monitor and communicate risk management activities and results
Information Security Program Development and Management
Objective 3.1 · Develop and manage an information security program that aligns with business objectives
Security Program Implementation and Operations
Objective 3.2 · Implement and operate an information security program
Security Awareness, Training, and Education
Objective 3.3 · Develop and deliver information security awareness and training programs
Security Program Metrics, Evaluation, and Improvement
Objective 3.4 · Monitor, evaluate, and continuously improve the security program
Incident Management and Response Planning
Objective 4.1 · Establish and maintain an incident response plan
Incident Detection, Triage, and Analysis
Objective 4.2 · Detect, triage, and analyze security incidents
Incident Response Execution and Containment
Objective 4.3 · Execute incident response activities, containment, and eradication
Post-Incident Recovery, Lessons Learned, and Reporting
Objective 4.4 · Conduct post-incident recovery, lessons learned, and reporting
Business Continuity and Disaster Recovery Integration
Objective 4.5 · Integrate incident management with business continuity and disaster recovery
Free CISM practice questions with full explanations. Test what you learn chapter by chapter.
CISM Practice Questions