Certified Information Security Manager (CISM)
Credential: Certified Information Security Manager (CISM)
Credentialing Agency: ISACA
Renewal Period: 3 years
The Certified Information Security Manager (CISM) is an advanced certification for the individual who designs, builds, and manages an enterprises information security. CISM focuses on information risk management as the basis of information security. It also includes material on broader issues such as how to govern information security as well as on practical issues such as developing and managing an information security program and managing incidents. This certification is targeted toward experienced information security managers and those who have information security management responsibilities. Five or more years of information security work experience, with a minimum of three years of information security management work experience is required.
More information can be found on the certifying agency's website.
Certified Information Security Manager (CISM)
MINIMUM REQUIREMENTS
Eligibility Requirements (View Details)
- Credential Prerequisite
- Experience: 5 years
- Education
- Training
- Membership
- Other
- Fee
Note: This credential may have multiple options for becoming eligible. Listed are the minimum requirements based on the minimum degree required. To view other options, see the Eligibility tab.
Exam Requirements (View Details)
- Exam
- Written Exam
- Oral Exam
- Practical Exam
- Performance Assessment
RECERTIFICATION SUMMARY
Renewal Period: 3 years
AGENCY CONTACT INFORMATION
ISACA
3701 Algonquin Road
Suite 1010
Rolling Meadows, IL 60008
Phone: 847-660-5505
Fax: (847) 253-1443
Contact Page
Education and/or Experience REQUIREMENTS
Submit verified evidence of a minimum of five years of information security work experience, with a minimum of three years of information security management work experience in three or more of the job practice analysis areas.
Experience Substitutions
The following security-related certifications and information systems management experience can be used to satisfy the indicated amount of information security work experience.
- Two Years:
- Certified Information Systems Auditor (CISA) in good standing
- Certified Information Systems Security Professional (CISSP) in good standing
- Post-graduate degree in information security or a related field (e.g., business administration, information systems, information assurance)
- One Year:
- One full year of information systems management experience or general security management experience
- Currently holding a skill-based security or general security certifications (e.g., SANS Global Information Assurance Certification (GIAC), Microsoft Certified Systems Engineer (MCSE), CompTIA Security+)
- Completion of an information security management program at an institution aligned with the Model Curriculum
The experience substitutions will not satisfy any portion of the three-year information security management work experience requirement.
Exception: Two years as a full-time university instructor teaching the management of information security can be substituted for every 1 year of information security experience.
Other REQUIREMENTS
The Certified Information Security Manager (CISM) credential has the following other requirements:
- Adhere to the ISACA Code of Professional Ethics
Written Exam
- Information Security Governance (24%)
- Information Risk Management and Compliance (33%)
- Information Security Program Development and Management (25%)
- Information Security Incident Management (18%)
Exam Preparation Resources
There are a number of resources available to help you prepare for the Certified Information Security Manager (CISM) examination:
- Best Sources
- General References
Testing Information
Testing for this credential is handled by PSI. The test centers are located in the U.S.
To find out more, use the following links on the PSI website:
For more information on the ISACA testing process, visit the agency website.
RECERTIFICATION
Certified Information Security Manager (CISM)
Renewal Period: 3 years