Free CISM Exam Flashcards
Memorize 50 essential terms and definitions for the ISACA Certified Information Security Manager (CISM). See the term, recall the definition, then flip to check yourself.
The Security Manager Mindset
CISM tests management judgment, not deep technical skill. The best answer usually defines direction, assigns ownership, aligns to business objectives, and produces evidence management can use — not the most technical fix.
Filter by Topic
Jump to Card
About These CISM Flashcards
These 50 flashcards are designed to help you memorize key terms and definitions for the ISACA Certified Information Security Manager (CISM). Each card shows a term on the front and its definition on the back—the classic flashcard format for vocabulary memorization. Use these alongside our practice questions to build both recall and comprehension.
Topics Covered
Frequently Asked Questions
What are the four CISM domains?
ISACA's CISM exam covers four domains: Information Security Governance (17%), Information Security Risk Management (20%), Information Security Program (33%), and Incident Management (30%). The Program and Incident Management domains together carry roughly 63% of the exam, reflecting CISM's management and execution focus.
What is the CISM passing score?
CISM uses a scaled score from 200 to 800, and a score of 450 or higher is required to pass. The scaled score is not a percentage of correct answers; it normalizes difficulty across exam forms. Candidates receive a preliminary result at the test center and an official score after ISACA review.
How is the CISM exam structured?
The CISM exam has 150 multiple-choice questions with a 4-hour (240-minute) time limit. Items emphasize the security manager's perspective — what to decide, fund, communicate, and improve — rather than deep technical implementation. The exam is delivered at PSI test centers or via remote online proctoring.
What experience is required for CISM certification?
Anyone may sit the CISM exam, but certification requires five years of professional information security management experience. Experience waivers of up to two years are available for certain credentials and education. Candidates must apply for certification within five years of passing the exam.
When does the CISM exam content outline change?
ISACA states the CISM Exam Content Outline updates effective 3 November 2026. Candidates testing before that date should study the current four-domain outline and avoid mixing it with the later blueprint. Maintaining certification requires 120 CPE hours per three-year reporting cycle plus annual maintenance fees.
Explore More ISACA Certifications
Continue into nearby exams from the same family. Each card keeps practice questions, study guides, flashcards, videos, and articles in one place.
More From This Family
Videos and articles for deeper review.