← Back to catalogue
Certification preparation

CISM: manage security, risk, and incidents

Prepare for CISM through governance, risk management, security programs, and banking and APS incident scenarios.

ISACAAvailable
ISACACIM8 lessons
Current outline before November 3, 2026: domains 17/20/33/30%. Exam of 150 questions in 240 minutes, passing 450 on the 200–800 scale without percentage equivalence. Update announced for November 3 with weights 18/20/33/29% and new architecture areas; full future coverage is not yet claimed. Portuguese is not among official languages listed in the guide. Passing an exam differs from earning certification, which requires experience and other ISACA conditions.

Objectives and progression

Eight lessons, 50 questions, and eight original cases with an internal 32-decision assessment in 50 minutes. Fictional banking examples connect investment, obsolescence, exceptions, suppliers, APS transition, containment, and recovery. This course follows the current outline before November 3, 2026, weighted 17/20/33/30%. ISACA announced an update for that date with weights 18/20/33/29% and new architecture areas. This first pass does not yet claim full coverage of the new outline.

Audience: Security managers, IT project managers, APS owners, and technology-risk professionals.

Prerequisites: IT and security fundamentals. ISACA certification requires the exam, validated experience, and other requirements; normally five years covering at least three domains, subject to eligible waiver rules. The exam may be taken before meeting experience requirements. Confirm individual requirements with ISACA; completing DR does not award certification.

290 estimated study minutes

  • Connect security decisions to business objectives and responsibilities.
  • Build proposals and reporting that enable informed decisions.
  • Interpret exposure, controls, and estimates without overstating precision.
  • Keep risk decisions valid when deadlines, threats, and dependencies change.
  • Connect assets, resources, design, and metrics to executable controls.
  • Assess evidence, shared responsibility, and secure service exit.
  • Define criteria, authority, communication, and recovery before an incident.
  • Coordinate evidence, communication, and return-to-service criteria.

Modules

  1. Governance, strategy, and authority
  2. Policies, investment, and reporting
  3. Assess risk and uncertainty
  4. Treat, monitor, and escalate risk
  5. Develop the security program
  6. Manage controls, suppliers, and lifecycle
  7. Prepare response and continuity
  8. Contain, recover, and learn

Continue learning

Cybersecurity

References and version

CISM current outline before November 3, 2026

What you will explore

0 / 8

Learning is also trying.

Original explained questions, flashcards, and scenarios to apply the concepts.

Practice
This module covers foundations. It is not a complete certification course or a full simulation of the official exam.

Exam domains

Information Security Governance17%
Information Security Risk Management20%
Information Security Program33%
Incident Management30%