Courseiva
CISMFree Study Guide

Certified Information Security ManagerThe Complete Beginner's Guide

This guide covers all key domains and objectives for the CISM certification, focusing on information security governance, risk management, program development, and incident management.

17 chapters
~3 hours total read
Free — no signup required
By Johnson Ajibi · Senior Network & Security Engineer · MSc IT Security

How to use this guide

This guide works best as a loop: read a chapter, test yourself with practice questions, look up unfamiliar terms in the glossary, then move to the next chapter.

① Read a chapter② Answer practice questions③ Review missed answers④ Repeat
Study Chapters

17 chapters covering every exam objective. Each chapter includes key concepts, exam tips, common traps, comparison tables, and a 5-question quiz at the end.

Start Chapter 1
Practice Questions

Free timed and untimed practice with instant feedback and full explanations. Pick 10–120 questions per session. Filter by domain to drill your weak areas.

Go to practice test
Glossary

Every CISMterm defined and searchable. Use it when a chapter mentions a concept you haven't seen before or want a quick refresher on.

Browse glossary
Exam Overview

Exam blueprint, domain weights, passing score, duration, cost, and registration links. Start here if you're new to this certification.

View exam guide

Chapters — CISM

1

Introduction to Information Security Governance

Objective 1.1 · Establish and maintain an information security governance framework

12m
2

Strategic Alignment and Security Strategy Development

Objective 1.2 · Align information security strategy with business goals and objectives

12m
3

Governance Roles, Responsibilities, and Reporting

Objective 1.3 · Define and communicate information security roles and responsibilities

12m
4

Governance Metrics, Monitoring, and Reporting

Objective 1.4 · Establish and maintain information security metrics and reporting

12m
5

Information Risk Management Concepts and Frameworks

Objective 2.1 · Establish and maintain a process for information risk management

12m
6

Risk Assessment Methodologies and Analysis

Objective 2.2 · Identify and analyze information security risks using established methodologies

12m
7

Risk Treatment, Response, and Mitigation

Objective 2.3 · Select and implement appropriate risk treatment and response strategies

12m
8

Risk Monitoring, Reporting, and Communication

Objective 2.4 · Monitor and communicate risk management activities and results

12m
9

Information Security Program Development and Management

Objective 3.1 · Develop and manage an information security program that aligns with business objectives

12m
10

Security Program Implementation and Operations

Objective 3.2 · Implement and operate an information security program

12m
11

Security Awareness, Training, and Education

Objective 3.3 · Develop and deliver information security awareness and training programs

12m
12

Security Program Metrics, Evaluation, and Improvement

Objective 3.4 · Monitor, evaluate, and continuously improve the security program

12m
13

Incident Management and Response Planning

Objective 4.1 · Establish and maintain an incident response plan

12m
14

Incident Detection, Triage, and Analysis

Objective 4.2 · Detect, triage, and analyze security incidents

12m
15

Incident Response Execution and Containment

Objective 4.3 · Execute incident response activities, containment, and eradication

12m
16

Post-Incident Recovery, Lessons Learned, and Reporting

Objective 4.4 · Conduct post-incident recovery, lessons learned, and reporting

12m
17

Business Continuity and Disaster Recovery Integration

Objective 4.5 · Integrate incident management with business continuity and disaster recovery

12m

Ready to test your knowledge?

Free CISM practice questions with full explanations. Test what you learn chapter by chapter.

CISM Practice Questions