All programmes

Certified Information Security Manager (CISM)

Study level Professional
Field Information Security

What this programme is about

CISM is aimed less at configuring firewalls and more at leading the security programme around them. It is a professional certification for people moving into information-security management, governance and risk.

The qualification centres on how organisations build, operate and improve security programmes rather than on one technical platform.

You will encounter governance, risk management, programme development and incident management. That makes CISM especially relevant if your work sits between technical teams and senior decision-makers.

Experience matters. This is not usually the first certification someone takes when entering cybersecurity because the credential is designed around professional security-management responsibilities.

Preparation courses can help you structure your study, but certification requirements are set by the awarding body and can change over time.

Before enrolling with a training provider, confirm the current exam domains, experience requirements, fees and renewal rules directly with ISACA. Professional certification rules can change, so the awarding body's current requirements should take priority over provider marketing.

What you'll cover

Information Security Governance Information Risk Management Security Programme Development Security Programme Management Incident Management Security Strategy Risk Treatment Security Metrics Policy and Governance Business Alignment

Capabilities you'll strengthen

Security Governance Risk Management Programme Leadership Incident Oversight Security Strategy Policy Development Stakeholder Communication Security Metrics Control Evaluation Business Risk Analysis

Where this qualification can support you

Information Security Manager
Cybersecurity Manager
Security Governance Lead
Security Programme Manager
Risk Manager
GRC Manager
Information Security Consultant
Security Operations Manager
Security Director
Cyber Risk Lead

What preparing for this qualification is like

Information-security governance deals with aligning security priorities with organisational goals and accountability.

Risk management focuses on identifying threats, assessing business impact and deciding how risks should be treated.

Security programme development moves from policy into implementation. You learn how controls, resources and responsibilities fit into a broader management framework.

Incident management covers preparation, response and recovery when security events occur.

The qualification expects you to think at management level. Technical details still matter, but the emphasis is on decisions, ownership and business impact.

Because CISM is a professional credential rather than a degree, always separate exam preparation from the official certification requirements set by ISACA.

Is this likely to suit you?

Good fit if you...

  • You already work in information security or a related field.
  • You want to move toward management or governance.
  • You are comfortable discussing risk with business leaders.
  • You want a recognised professional security credential.
  • You prefer strategic responsibility over purely hands-on technical work.

Think twice if you...

  • You are completely new to cybersecurity.
  • You want a certification focused mainly on penetration testing.
  • You have little interest in governance or risk.
  • You have not checked the current experience requirements for certification.

Eligibility and requirements

Training-course entry requirements vary by provider. The official CISM certification has its own examination and professional-experience requirements set by ISACA. A background in information security, risk, governance or IT management is especially useful. Always verify the current eligibility, exam, experience and renewal requirements directly with ISACA before enrolling or applying for certification.

Common questions

Is CISM an entry-level certification?
Generally no. It is aimed at professionals with security-management responsibilities or experience.
Is CISM technical?
It assumes security knowledge, but the emphasis is management, governance, risk and programme oversight.
Who awards CISM?
CISM is awarded by ISACA.
Do I need work experience?
The certification has professional-experience requirements. Check ISACA for the current rules.
What roles is CISM useful for?
It is commonly relevant to security management, GRC, risk and programme-leadership roles.
Still comparing?

Compare related programmes before you decide.

Compare qualifications, subject areas and the institutions offering each programme.

Explore similar programmes

Programme structures, duration and admission requirements can vary by institution and country. Always confirm current details with the institution before applying.