CISM: Certified Information Security Manager Practice Exam — CISM: Certified Information Security Manager

1. The question bank is cloud‑connected and updates automatically; no manual re‑acquisition is required.

2. Start practicing right after activating the question bank. It supports simultaneous use on websites and mini‑programs, with one‑click bilingual switching for each question.

3. Functions include online practice, mock tests, note‑taking, wrong‑question recording, etc., valid for one year.

4. Recommended practice order: Turn on review mode to browse questions → Complete sequential practice → Take mock exams for pre‑test self‑assessment.

5. Activation codes can be purchased by clicking Buy Now on the right or via our official Tmall flagship store.

6. For inquiries, contact customer service through mini‑program, WeChat, WhatsApp or LINE.

Exam information

CISM (Certified Information Security Manager) Latest Complete Exam Information

Basic Exam Information

- Exam Languages: Multiple language options are available, including Simplified Chinese, Traditional Chinese, English, Japanese, etc., with globally unified language selections.

- Registration Eligibility: There are no restrictions for exam registration, and all candidates may sit for the exam. However, formal CISM credential application is required after passing the exam. Credential application prerequisites:

 • Minimum 5 years of professional experience in information security, with 3 years concentrated in four core information security management domains (strategy, program management & implementation, security governance, incident management)

 • Education‑based experience exemptions: A 4‑year bachelor’s degree deducts 1 year; a master’s degree deducts 1 year; an information‑security‑focused bachelor’s degree deducts 1 year

 • Relevant certifications (e.g., CISSP, CISA, CRISC) deduct 1 year

 • Compliance with the ISACA Code of Professional Ethics

- Exam Fees: USD 575 for ISACA members, USD 760 for non‑members; an additional USD 50 certification fee is required for credential application upon passing the exam.

- Exam Duration: 4 hours (240 minutes), covering time for answering all exam questions.

- Exam Format:

 • Global Standard: Two modes are available – remote‑proctored online exams (video proctoring via PSI) and in‑person computer‑based testing (CBT).

 • Special Rule for Mainland China: Only in‑person CBT at authorized test centers is available (arranged by ISACA‑authorized partners).

- Exam Content: Comprises 150 multiple‑choice questions, all scored with no unscored pre‑test items.

- Score Information:

 • A preliminary pass/fail score report is available immediately after the exam

 • Official exam results are sent via email within 10 working days post‑exam

 • Passing score: 450 out of a full score of 800 (200‑800 scoring scale)

- Exam Eligibility Validity: After successful registration, candidates must book and complete the exam within 12 months; exam eligibility expires if overdue.

- Reschedule & Cancellation Policy: Rescheduling or cancellation must be completed at least 48 hours prior to the exam appointment; no changes are allowed within 48 hours before the exam start time.


---


Detailed Exam Content (Current Exam Outline Valid until November 3, 2026)

The CISM exam covers four core knowledge domains with a total weightage of 100%, focusing on the management capabilities and practical application of information security managers.


1. Information Security Governance 17% :Corporate governance culture, regulations and frameworks, information security strategy formulation, governance standards, budget & resource planning, business case development

2. Information Security Risk Management 20% :Risk assessment and analysis, vulnerability & control deficiency analysis, risk response options, risk & control ownership, risk monitoring and reporting

3. Information Security Program Development and Management 33% :Program resource management, security policy & procedure formulation, security awareness training, vendor management, security metrics and performance evaluation

4. Information Security Incident Management 30% :Incident detection, investigation, response and recovery planning, business impact analysis (BIA), business continuity & disaster recovery, incident communication and reporting


Upcoming 2026 November 3 Exam Outline Update

- Weightage of Risk Management (Domain 2) will increase to 33%, becoming the largest domain

- New content on enterprise architecture and information security architecture will be added

- Greater emphasis will be placed on information security strategy and program development

- New study materials will be released on September 1, 2026



Registration Process

Global Standard Registration Process

1. Visit the [official global ISACA website](https://www.isaca.org/) to create and log into a MyISACA account

2. Register for the CISM exam, fill in personal information, work experience and other relevant details

3. Pay the exam fee (USD 575 for members / USD 760 for non‑members)

4. Receive an Authorization to Test (ATT) notification via email within 1‑3 working days upon successful payment, including candidate ID and 12‑month eligibility validity

5. Log into the ISACA account, click Certification & CPE Management, then click Schedule Your Exam

6. Redirect to the PSI dashboard to select exam time, location and format (only in‑person CBT available for Mainland China)

7. Save the PSI appointment confirmation email received

8. Present valid ID documents matching registration information on exam day


Special Registration Process for Mainland China Candidates

1. Register via the [ISACA China official website](https://www.isaca.org.cn/) or ISACA‑authorized partners such as ZhongShen Audit Online

2. Adopt the mode of institutional registration & payment followed by individual exam scheduling

3. Submit personal information, academic certificates and other documents for institutional‑assisted registration

4. Pay the exam fee (USD 575 for members / USD 760 for non‑members) and complete registration procedures via authorized institutions

5. Independently book in‑person test centers in Mainland China via the PSI platform after receiving the ATT notification

6. Present valid ID documents (ID card or passport) on exam day



Supplementary Notes

1. Credential Validity: The CISM credential is valid for 3 years. Holders must earn 120 Continuing Professional Education (CPE) credits and pay renewal fees to maintain credential validity.

2. Retake Policy: Candidates who fail the exam must wait 30 days for a retake; a 90‑day waiting period is required after two consecutive failures. Retake fees are the same as initial exam fees.

3. Exam Update: The new exam outline will take effect on November 3, 2026. A major update to the exam question bank is scheduled after this date.



Wish all candidates success in their exams!

Sample questions

CISM: Certified Information Security Manager · Q1
Question #1 An information security risk analysis BEST assists an organization in ensuring that:
  • A.
    the infrastructure has the appropriate level of access control.
  • B.
    cost-effective decisions are made with regard to which assets need protection
  • C.
    an appropriate level of funding is applied to security processes.
  • D.
    the organization implements appropriate security technologies

Answer: B

Option Analysis: A. Incorrect, as validating appropriate access control levels for infrastructure is a specialized control assessment activity, not the primary objective of risk analysis. B. Correct, as risk analysis evaluates asset value, associated threats, and vulnerabilities to prioritize protection efforts and enable cost-effective risk treatment decisions aligned with business impact. C. Incorrect, as allocating appropriate funding to security processes is a separate budget governance activity that risk analysis may inform but does not directly ensure. D. Incorrect, as implementing appropriate security technologies is a risk treatment execution step that occurs after risk analysis, not an outcome of the analysis itself. Key Concept: Information security risk analysis quantifies and qualifies potential business impacts of risks to organizational assets to support data-driven, cost-effective risk treatment and security investment decisions aligned with business priorities. References: ISACA CISM Exam Content Outline, ISACA Risk IT Framework
CISM: Certified Information Security Manager · Q2
Question #2 In a multinational organization, local security regulations should be implemented over global security policy because:
  • A.
    business objectives are defined by local business unit managers.
  • B.
    deploying awareness of local regulations is more practical than of global policy.
  • C.
    global security policies include unnecessary controls for local businesses.
  • D.
    requirements of local regulations take precedence.

Answer: D

Option Analysis: A. Incorrect, as business objectives for multinational organizations are aligned across global and local levels to support overall organizational strategy, and this is not a valid reason to prioritize local regulations over global policy. B. Incorrect, as the practicality of deploying awareness training for local regulations versus global policy is an operational implementation concern, not a governance mandate justifying priority of local regulations. C. Incorrect, as unnecessary controls in global policy for local contexts are an efficiency consideration, not the core justification for prioritizing local regulatory requirements over global policy. D. Correct, as local security regulations are legally binding mandates in the jurisdictions where an organization operates, so their requirements inherently take precedence over internal global security policy to avoid compliance penalties. Key Concept: Under CISM information security governance principles, mandatory legally binding local regulatory requirements take priority over internal organizational global security policies for operations in the relevant jurisdiction to meet compliance obligations. References: ISACA CISM Exam Content Outline, ISACA Information Security Governance Framework
CISM: Certified Information Security Manager · Q3
Question #3 To gain a clear understanding of the impact that a new regulatory requirement will have on an organization's information security controls, an information security manager should FIRST:
  • A.
    conduct a cost-benefit analysis.
  • B.
    conduct a risk assessment.
  • C.
    interview senior management.
  • D.
    perform a gap analysis.

Answer: D

Option Analysis: A. Incorrect, as a cost-benefit analysis is used to evaluate the financial viability of control adjustments after gaps between existing controls and the new regulation are identified, so it is not the appropriate first step. B. Incorrect, as a risk assessment quantifies the likelihood and impact of security threats to assets, which occurs after gaps between current controls and the new regulatory requirement are identified, so it is not the first step. C. Incorrect, as interviewing senior management is typically done to align on risk tolerance and remediation priorities after gaps related to the new regulation are first identified, so it is not the initial step. D. Correct, as a gap analysis compares the organization’s current information security controls against the requirements of the new regulation to directly identify control insufficiencies, which is the essential first step to understand the regulation’s impact on controls. Key Concept: The first step to assess the impact of a new regulatory requirement on an organization’s existing information security controls is to perform a gap analysis to identify discrepancies between the current control state and mandatory regulatory control requirements. References: ISACA Gap Analysis for Information Security Compliance, https://www.isaca.org/resources/isaca-journal/issues/2019/volume-3/gap-analysis-for-information-security-compliance ISACA CISM Exam Content Outline
CISM: Certified Information Security Manager · Q4
Question #4 When management changes the enterprise business strategy, which of the following processes should be used to evaluate the existing information security controls as well as to select new information security controls?
  • A.
    Access control management
  • B.
    Change management
  • C.
    Configuration management
  • D.
    Risk management

Answer: D

Option Analysis: A. Access control management is focused on regulating user and system access to organizational assets, so it is not the appropriate process for evaluating and selecting overarching information security controls in response to business strategy changes, making this option incorrect. B. Change management governs structured, low-disruption implementation of adjustments to systems, processes, and infrastructure, so it does not serve the purpose of evaluating and selecting security controls aligned with updated business strategy, making this option incorrect. C. Configuration management maintains consistent, documented configurations of organizational assets and systems, so it is not used to evaluate or select information security controls following a business strategy change, making this option incorrect. D. Risk management is the process of identifying, assessing, and treating organizational risks aligned with business objectives, so it is the correct process for evaluating existing controls and selecting new controls when enterprise business strategy changes, making this option correct. Key Concept: Aligning information security controls with changing enterprise business strategy requires use of the risk management process to ensure controls address updated risk priorities, risk appetite, and business objectives. References: ISACA CISM Exam Content Outline, NIST SP 800-30 Rev. 1: Guide for Conducting Risk Assessments, https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final
CISM: Certified Information Security Manager · Q5
Question #5 Which of the following is the BEST way to build a risk-aware culture?
  • A.
    Periodically change risk awareness messages.
  • B.
    Ensure that threats are communicated organization-wide in a timely manner.
  • C.
    Periodically test compliance with security controls and post results.
  • D.
    Establish incentives and a channel for staff to report risks.

Answer: D

Option Analysis: A. A is incorrect because periodically changing risk awareness messages is a minor engagement tactic that does not drive sustained, proactive risk-aware decision-making across all staff. B. B is incorrect because timely organization-wide threat communication is a reactive risk notification practice, not a foundational driver of long-term risk-aware culture. C. C is incorrect because periodic compliance control testing and result publication only measures adherence to existing security rules, rather than encouraging voluntary, proactive risk identification by staff. D. D is correct because establishing incentives and a clear reporting channel for staff to report risks actively motivates all employees to integrate risk consideration into their daily work, which forms the core of a strong risk-aware culture. Key Concept: The most effective way to build a risk-aware culture is to implement mechanisms that empower and incentivize all staff to proactively participate in risk identification and reporting as a standard part of their job responsibilities. References: ISACA CISM Review Manual 16th Edition, ISACA Building a Risk-Aware Culture to Enhance Cybersecurity Resilience, https://www.isaca.org/resources/isaca-journal/issues/2021/volume-3/building-a-risk-aware-culture-to-enhance-cybersecurity-resilience

FAQ

How many practice questions are available for CISM: Certified Information Security Manager?

This question bank includes 1250 CISM: Certified Information Security Manager practice questions covering single and multiple choice, each with answers and explanations.

Are CISM: Certified Information Security Manager practice questions available in Chinese and English?

Yes, CISM: Certified Information Security Manager practice questions are provided in both Chinese and English.

Can I try CISM: Certified Information Security Manager practice questions for free?

Yes. Free sample questions are available on this page, and the full question bank is available after signing up on Zhangxuetu.