Build and manage enterprise security programs using industry best practices and leadership.
Respond to security incidents, strengthen resilience, and support business continuity planning.
CISM is focused on information security management and business alignment, making it ideal for decision-makers and policy leaders, while CISSP is more technical in scope and suited to those working hands-on in security operations and engineering. As for CISA it focuses on auditing and assessing information systems, while CISM focuses on managing security programs; CISA is better for audit/compliance roles, while CISM targets security leadership positions.
A minimum of 5 years of professional information security management work experience within the CISM job practice areas is required for certification, and this experience must be gained within the 10 year period preceding the application date. You can take the exam before meeting this requirement, but you must apply within 5 years of passing the exam.
The CISM exam consists of 150 questions covering 4 job practice domains. It uses a 200 to 800 scaled scoring method rather than percentages, and a score of 450 or higher is required to pass.
CISM certification exams are computer-based and administered at authorized PSI testing centers globally or as remotely proctored exams, and registration is continuous candidates can register any time with no restrictions. Candidates can schedule a testing appointment as early as 48 hours after payment of exam registration fees.
Maintaining CISM requires earning a minimum of 20 CPE hours annually and a total of 120 CPE hours over a 3 year period, plus paying an annual maintenance fee