
CISM — Certified Information Security Manager · 2026 Edition
CISM Study Guide — 2026 Edition
Edition noteNew for 2026: written to ISACA's CISM outline in force for exams from 3 November 2026 (weights 18/20/33/29%).
Written to ISACA's updated CISM exam content outline, in force for exams from 3 November 2026: 233 original questions with worked explanations and a 150-question full-length practice exam.
- 233 original CISM practice questions, each with a worked explanation, in one PDF + EPUB you keep
PDF + EPUB · English · 128 pages · $24.99 one-time
This book is written in English.
Instant download after payment — no account needed, no subscription.
14-day money-back guarantee: not satisfied for any reason? Email support@preppass.org within 14 days of purchase for a full refund. Refund policy
Look inside the book
Three real pages, rendered straight from the PDF you download — a reference page, a teaching page, and a worked question, always in that order. Nothing here was redrawn to look better.
- Quick referenceSection 3 — Information Security Program (50 questions) · PDF page 93
A page you can turn back to: the numbers, deadlines or terms gathered in one place.
- How it's taughtSection 2 — Information Security Risk Management (30 questions) · PDF page 89
An explanation page: the material taught in prose, in the order the exam tests it.
- A question, workedSection 1 — Information Security Governance (27 questions) · PDF page 73
A practice question with its answer and the reasoning behind it — not just a key.
About the CISM exam
Information security managers and aspiring security leaders preparing for ISACA's CISM certification. This book teaches the management-level judgment the exam tests — governance, risk, program, and incident decisions — through original practice questions with worked explanations. It is an independent study guide, not affiliated with ISACA, and contains no real exam questions.
Outline changes: Domain weights changed to 18% / 20% / 33% / 29%, with enterprise architecture and information security architecture added as content areas and greater emphasis on strategy and program development.
| Awarding body | ISACA |
|---|---|
| Questions | 150 multiple-choice questions |
| Time limit | 4 hours (240 minutes) |
| Passing rule | Candidates must receive a scaled score of 450 or higher to pass the exam |
| Fees | ISACA member US$575; nonmember US$760 |
| Delivery | Computer-based at authorized testing centers and via remote proctoring |
| Eligibility | Five or more years of experience in information security management; certification application requires the experience, and waivers of up to 2 years are available |
| Retakes | Four attempts within a rolling 12-month period |
| Languages | English, Spanish, Chinese-Simplified, Japanese, French, German |
| Content outline | CISM Exam Content Outline, 2026 update — effective November 3, 2026 |
| Domains and weights |
|
Questions buyers ask
- How many questions are on the CISM exam, and how much time do I get?
- 150 multiple-choice questions in 4 hours (240 minutes).
- What is the passing score for CISM?
- Candidates must receive a scaled score of 450 or higher to pass. Scores are reported as scaled scores.
- What are the CISM domains and their weights?
- Information Security Governance 18%, Information Security Risk Management 20%, Information Security Program 33%, Incident Management 29%.
- Which exam outline version should I study for?
- It depends on your exam date. Exams from 3 November 2026 follow the updated outline, which adds enterprise architecture and information security architecture and emphasizes strategy and program development; exams before that date use the previous outline.
- What are the eligibility requirements for CISM certification?
- Certification requires five or more years of experience in information security management. You can sit the exam before meeting the experience requirement and apply for certification within five years of passing.
- How much does the CISM exam cost, and how many times can I retake it?
- US$575 for ISACA members, US$760 for nonmembers. You have four attempts within a rolling 12-month period.
- How is this book organized?
- Four chapters matching the exam domains, each closing with a quiz, plus a full-length 150-question practice exam. 233 original questions in total, every one with a worked explanation.
- Is CISM a technical or a management exam?
- Management. The exam puts greater emphasis on information security strategy and program development, and governance is the strategy, expectations, and policy layer — candidates who answer as technicians choose the wrong option. This book's explanations say why the technical option is not the manager's first action.
- Which CISM — Certified Information Security Manager study guide should I use?
- It depends on what you already have. ISACA: CISM Review Manual (print and digital) and exam content outline — choose ISACA's manual if you want the review text published by the exam body; check that its edition matches your exam date. McGraw Hill: CISM Certified Information Security Manager All-in-One Exam Guide, Second Edition, from $60.00 — choose it if you sit the exam before 3 November 2026 and want a guide written to the outline in force until then. This PrepPass guide: 128 pages, 233 practice questions with explanations, PDF + EPUB, $24.99 one-time — choose this book if you sit the exam on or after 3 November 2026, when the updated outline applies. Prices were checked on 2026-09-24; confirm them with each seller.
- Is a study guide enough for the CISM — Certified Information Security Manager exam, or do I need a course?
- Check eligibility first — per ISACA: five or more years of experience in information security management; certification application requires the experience, and waivers of up to 2 years are available. A book does not replace those requirements. For the exam content itself, this 128-page guide teaches the material chapter by chapter with 233 practice questions and explanations inside. A prep course adds live instruction and a set schedule; whether you need one beyond any required education is your call.
- Does the CISM — Certified Information Security Manager study guide come as a PDF?
- Yes — CISM Study Guide — 2026 Edition downloads as PDF and EPUB, 128 pages. The download link is emailed the moment payment clears and does not expire.
- How much does the CISM — Certified Information Security Manager study guide cost?
- $24.99, once. There is no subscription and no account to create; the PDF and EPUB files are yours to keep.
- Can I read part of the CISM — Certified Information Security Manager study guide before buying?
- Yes. A full chapter is free to read on this page — not a summary of one, the chapter itself.
- Is this the official CISM — Certified Information Security Manager study guide?
- No. This is an independent study guide and is not affiliated with or endorsed by the exam's awarding body. It is written from ISACA's CISM exam content outline (2026 update) and candidate guide, with NIST CSF 2.0 and SP 800-series publications. Always confirm current requirements with the body that issues your licence.
How this book compares
ISACA updates the CISM exam content outline for exams from 3 November 2026. This book is written to the updated outline; McGraw Hill's All-in-One guide is written to the 2022 outline in force before then.
| Resource | Price | What you get | Choose it if |
|---|---|---|---|
| This bookCISM Study Guide — 2026 EditionPrepPass | $24.99 | Independent downloadable study guide for CISM
| Choose this book if you sit the exam on or after 3 November 2026, when the updated outline applies. |
| From the exam bodyCISM Review Manual (print and digital) and exam content outline (opens the publisher's page in a new tab)ISACA | Price not listed on the page we checked | The exam body's review manual and published outline
| Choose ISACA's manual if you want the review text published by the exam body; check that its edition matches your exam date. |
| AlternativeCISM Certified Information Security Manager All-in-One Exam Guide, Second Edition (opens the publisher's page in a new tab)McGraw Hill | From $60.00 | Printed and eBook exam guide by Peter H. Gregory
| Choose it if you sit the exam before 3 November 2026 and want a guide written to the outline in force until then. |
This book
CISM Study Guide — 2026 Edition
PrepPass
- Price
- $24.99
- What you get
Independent downloadable study guide for CISM
- 233 original questions, each explained and cited
- 128 pages, PDF + EPUB
- Choose it if
- Choose this book if you sit the exam on or after 3 November 2026, when the updated outline applies.
From the exam body
ISACA
- Price
- Price not listed on the page we checked
- What you get
The exam body's review manual and published outline
- ISACA notes the exam content outline is updated effective 3 November 2026
- Choose it if
- Choose ISACA's manual if you want the review text published by the exam body; check that its edition matches your exam date.
Alternative
McGraw Hill
- Price
- From $60.00
- What you get
Printed and eBook exam guide by Peter H. Gregory
- Covers all 2022 CISM exam domains
- 300 practice questions online in the TotalTester exam engine
- Choose it if
- Choose it if you sit the exam before 3 November 2026 and want a guide written to the outline in force until then.
Other resources' prices and contents are as listed on each publisher's or seller's own page, checked September 24, 2026. Prices change; confirm on the linked page before you buy. This book's price and contents come from our own catalog.
Sources (2)
- https://www.isaca.org/credentialing/cism — read September 24, 2026
- https://www.mheducation.com/highered/mhp/product/cism-certified-information-security-manager-all-one-exam-guide-second-edition.html — read September 24, 2026
What's included — and what isn't
Included
- Four chapters, one per domain of ISACA's CISM outline effective 3 November 2026
- A quiz closing each chapter, with worked explanations
- A 150-question full-length practice exam at the 2026 outline weights
- 233 original questions, each explained and cited to its source
- Taught from NIST CSF 2.0, the NIST SP 800 series and ISACA's own outline
- PDF + EPUB you keep
Not included
- No printed copy is shipped — this is a file you download and can print yourself
- No video course, instructor, tutoring or online question bank comes with the book — everything is in the file
- Not your exam registration or the testing centre's fee, which you still pay to the official body
Contents
See 10 sections and the page each one starts on
- Chapter 1 — Information Security Governancep. 6
- Chapter 2 — Information Security Risk Managementp. 19
- Answer key & explanationsp. 28
- Chapter 3 — Information Security Programp. 31
- Chapter 4 — Incident Managementp. 50
- Section 1 — Information Security Governance (27 questions)p. 67
- Section 2 — Information Security Risk Management (30 questions)p. 78
- Section 3 — Information Security Program (50 questions)p. 90
- Section 4 — Incident Management (43 questions)p. 109
- Answer key & explanations — Section 4p. 119
Taken from the PDF you download, with the page each one starts on — not typed here.
Read a chapter free, in full
One complete chapter, exactly as it ships in the eBook. Scroll the window to read it right here; no download, no email.
Read chapter 3 here, without leaving the page
We didn't give you the easy intro — the free chapter opens on one of the hardest-working parts of the book, so you can judge the teaching where the exam gets difficult.
This is the largest domain on the exam, and it has two halves. Development is design: the resources the program needs, the assets it protects, the standards it follows, the policies that authorize it, and the metrics that prove it works. Management is operation: selecting and implementing controls, testing them, training people, managing suppliers, and reporting upward. It also covers the 2026 outline's two new content areas — enterprise architecture and information security architecture[1] — and the outline's "greater emphasis on ... program development"[1] makes the first half a heavier exam topic than before.
3.1 Program resources: people, tools, and technologies
A program is only as real as its resources. The manager must secure skilled people, appropriate tools, and sustainable funding — and the 2026 outline's "greater emphasis on ... program development"[1] makes this a heavier exam topic than before. Resource planning starts from the strategy: what must the program achieve, and what does that require?
Two management principles govern resourcing. First, resources follow risk: the highest-priority risks get the first resources, not the loudest stakeholders. Second, people are the scarcest resource — hiring, retaining, and developing security talent is a program activity, not an HR afterthought. Tools amplify people; they do not replace judgment.
The exam-ready takeaway: resource decisions are risk decisions. Fund what retires the most risk first.
3.2 Identifying and classifying information assets
You cannot protect what you have not identified. Asset identification inventories the information and systems that matter; classification assigns each a protection level based on the harm its compromise would cause.
The foundation is the CIA triad, defined by FIPS 199: "a loss of confidentiality is the unauthorized disclosure of information"[2]; "a loss of integrity is the unauthorized modification or destruction of information"[2]; "a loss of availability is the disruption of access to or use of information or an information system"[2]. Classification schemes (public / internal / confidential / restricted, or similar) operationalize these definitions: the classification tells the custodian which protective measures apply.
Two governance points matter. First, classification must reflect business impact, not IT convenience — the data owner, who understands the business harm, drives the classification. Second, classification without handling procedures is decoration: each level must map to concrete protections for storage, transmission, and disposal.
The exam-ready takeaway: classify by business impact on confidentiality, integrity, and availability — then tie every level to handling rules.
3.3 Industry standards and frameworks
The program does not invent its structure; it adopts and adapts proven ones. Practitioners are expected to "support the implementation of, and encourage compliance with, appropriate standards and procedures for the effective governance and management of enterprise information systems and technology"[3]. The NIST family used throughout this book — the CSF for governance structure, SP 800-53 for controls ("safeguards or countermeasures ... to protect the confidentiality, integrity, and availability of the system and its information"[4]), SP 800-30 for risk assessment — is one such family; the principle generalizes.
Framework selection is a management decision with exam-testable criteria: fit to the organization's size and sector, recognition by regulators and customers, and auditability. Adopting a framework the board and auditors already understand shortens every conversation about the program's design. Customization is expected — no framework fits unmodified — but deviations should be documented and justified, not silent.
The exam-ready takeaway: standards give the program legitimacy, comparability, and auditability. Choose by fit and recognition, then adapt openly.
3.4 Policies, procedures, and guidelines
The policy hierarchy translates strategy into enforceable rules:
- Policy — the "what" and "why": management's intent, mandatory, approved at senior level. "A formal policy provides the authority and guidance necessary to develop an effective contingency plan"[5] — and the same authority underwrites every other plan.
- Standards — mandatory specifics supporting policy (e.g., encryption algorithms, password rules).
- Procedures — the step-by-step "how," detailed enough that different people produce consistent results.
- Guidelines — recommended, not mandatory; guidance for situations needing judgment.
Policies fail in predictable ways: written by IT without business input, approved but never communicated, or so detailed they cannot survive contact with reality. The manager's test for any policy is enforceability — a rule the organization will not enforce teaches that rules are optional. Review cycles keep policies aligned with the strategy and the law; a policy that contradicts current regulation is a liability, not an asset.
The exam-ready takeaway: policy states intent with authority; procedures state steps; guidelines advise. If it cannot be enforced, it should not be policy.
3.5 Program metrics: proving the program works
"What gets measured gets managed" is only half true — what gets measured badly gets mismanaged. Security metrics must inform decisions, not decorate dashboards. NIST's measurement guide defines three types: "implementation measures to measure execution of security policy"[6]; "effectiveness/efficiency measures to measure results of security services delivery"[6]; and "impact measures to measure business or mission consequences of security events"[6].
The hierarchy matters: implementation measures show progress — they "demonstrate progress in implementing information security programs, specific security controls, and associated policies and procedures"[6] — but a fully implemented control that does not work is a comforting illusion. Effectiveness measures test whether controls achieve their purpose; impact measures connect security events to business consequences, the language leadership understands.
Good metrics share traits the exam tests: they are tied to objectives, reported to someone who can act, and trended over time — a single data point is trivia. Vanity metrics (raw alert counts, training completion percentages without behavior change) measure activity, not security.
The exam-ready takeaway: measure implementation, then effectiveness, then business impact — and report each to the audience that can act on it.
3.6 Control design and selection
Controls are selected to implement the risk responses Chapter 2 chose. "Security controls are the safeguards or countermeasures employed within a system or an organization to protect the confidentiality, integrity, and availability of the system and its information"[4]. Selection is risk-driven: the assessment identifies what must be protected and from what, and controls are chosen to reduce the prioritized risks to acceptable levels — not to implement every control in the catalog.
The manager thinks in layers and types. Preventive controls stop incidents, detective controls find them, corrective controls limit and repair damage — and a mature program needs all three, because no preventive control is perfect. The exam tests this thinking with scenarios where the "best" control depends on which risk is being treated: a detective control is the wrong answer to a risk that demands prevention, and vice versa.
The exam-ready takeaway: select controls from the risk assessment, not from the catalog — and cover prevent, detect, and correct.
3.7 Control implementation and integration
Implementation is where programs succeed or die quietly. A control that is purchased but not integrated into business processes is shelfware. Integration means the control fits how work actually gets done: access controls embedded in onboarding, logging built into system deployment, backup verification inside change management.
The manager's implementation duties are coordination and verification — confirming that controls are deployed as designed, that owners understand their responsibilities, and that exceptions are documented and approved rather than silently tolerated. Controls land best when they are part of the architecture from the start: organizational missions and business processes guide the development of the enterprise architecture[7], and security requirements integrated at that stage avoid the cost of bolting them on afterward.
The exam-ready takeaway: a control is not implemented until it operates inside the business process it protects.
3.8 Enterprise architecture and information security architecture
The 2026 outline adds two content areas: "enterprise architecture and information security architecture"[1]. The manager needs the concepts, not the architect's toolbox.
Enterprise architecture is "a management practice employed by organizations to maximize the effectiveness of mission/business processes and information resources in helping to achieve mission/business success"[7] — it is how the organization keeps its technology aligned with its missions as both evolve. It provides "a disciplined and structured methodology for managing the complexity of the organization's information technology infrastructure"[7], guided by mission and business processes.
Information security architecture is the security dimension of that practice: it "describes the security-related aspects of the enterprise architecture that are incorporated into the enterprise architecture definition as an integral part of the architecture development — that is a sub-architecture derived from the enterprise architecture, not a separately defined layer or architecture"[7]. The exam point is the relationship: security architecture derives from enterprise architecture; it is not a parallel universe. When the enterprise architecture changes — a cloud migration, a merger — the security architecture must change with it, and risk decisions documented "at all levels of the enterprise architecture" keep the reasoning traceable.
For the security manager, the practical consequences are three: new initiatives are reviewed against the architecture before approval, security requirements are integrated into architecture decisions rather than added later, and the architecture gives leadership a common language for discussing risk trade-offs.
The exam-ready takeaway: security architecture is derived from — never separate from — enterprise architecture, and both exist to keep technology serving the mission.
3.9 Control testing and evaluation
Testing answers the question implementation cannot: does the control work? The monitoring discipline requires determining "the ongoing effectiveness of risk response measures following implementation"[7] — and testing is how that determination is made. Testing takes many forms: vulnerability scans, penetration tests, control self-assessments, and audits each answer different questions, and the manager matches the method to the question.
Two distinctions carry exam weight. First, testing design versus testing operation: a well-designed control that nobody follows fails an operating-effectiveness test. Second, testing frequency follows risk: high-risk controls are tested more often, and any significant change triggers retesting. Test results feed the monitoring cycle — findings become remediation, remediation is verified, and the loop continues.
The exam-ready takeaway: test effectiveness, not just existence — and test high-risk controls most often.
3.10 Security awareness and training
People are both the strongest sensor network and the most exploited vulnerability. The program's answer is structured learning: "learning is a continuum; it starts with awareness, builds to training, and evolves into education"[8].
- Awareness — for everyone: the "what" and "why" that changes daily behavior (recognizing phishing, handling data correctly).
- Training — role-based: the skills specific jobs need (developers learn secure coding, executives learn incident escalation).
- Education — depth for specialists: the expertise security professionals build over careers.
The manager measures outcomes, not attendance — behavior change, not completion certificates (the metrics lesson in §3.5 applied). And awareness is continuous: threats evolve, staff turn over, and a one-time campaign decays.
The exam-ready takeaway: awareness for all, training by role, education for specialists — measured by behavior, repeated forever.
3.11 Managing external services and suppliers
Outsourcing does not outsource accountability. "Cybersecurity Supply Chain Risk Management (GV.SC): cyber supply chain risk management processes are identified, established, managed, monitored, and improved by organizational stakeholders"[9] — the organization owns this end to end.
The management lifecycle for suppliers runs: due diligence before the relationship, contractual requirements during negotiation, and ongoing monitoring for the relationship's duration. "The risks posed by a supplier, their products and services, and other third parties are understood, recorded, prioritized, assessed, responded to, and monitored over the course of the relationship"[9] — note "over the course of the relationship," not just at signing. And requirements belong in the contract: they are "established, prioritized, and integrated into contracts and other types of agreements with suppliers and other relevant third parties"[9].
The exam tests the failure modes: assuming a vendor's certifications replace your own due diligence, signing contracts without security terms, and treating supplier risk as a procurement problem rather than a security program responsibility.
The exam-ready takeaway: vet before signing, contract the requirements, monitor for the life of the relationship — accountability never transfers.
3.12 Communications and reporting to stakeholders
The program's reporting duty has two audiences and two languages. Leadership gets business consequences and decisions needed; operational teams get findings and actions. The ethics code reinforces the duty: practitioners must "inform appropriate parties of the results of work performed including the disclosure of all significant facts known to them that, if not disclosed, may distort the reporting of the results"[3] — reporting that hides bad news is an ethics violation, not a communication style.
Effective program reporting is regular, concise, and forward-looking: what changed since last time, what risk that creates, and what decision or resources it requires. It also closes the loop — reporting what was done about last period's findings builds the credibility that funds next period's initiatives.
The exam-ready takeaway: report decisions needed, disclose fully to entitled parties, and always close the loop on past findings.
Sources cited in this excerpt
- ISACA Updates CISM Exam Content Outline Factoring in Today's Technologies, Security Responsibilities (press release). 2026. https://www.isaca.org/about-us/newsroom/press-releases/2026/isaca-updates-cism-exam-content-outline-factoring-in-todays-technologies-security-responsibilities
- FIPS Publication 199, Standards for Security Categorization of Federal Information and Information Systems. National Institute of Standards and Technology (U.S. Department of Commerce), 2004-02. https://nvlpubs.nist.gov/nistpubs/FIPS/NIST.FIPS.199.pdf
- ISACA Code of Professional Ethics. retrieved 2026-09-22. https://www.isaca.org/code-of-professional-ethics
- NIST Special Publication 800-53 Revision 5, Security and Privacy Controls for Information Systems and Organizations. National Institute of Standards and Technology (U.S. Department of Commerce), 2020-09. https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-53r5.pdf
- NIST Special Publication 800-34 Revision 1, Contingency Planning Guide for Federal Information Systems. National Institute of Standards and Technology (U.S. Department of Commerce), 2010-05. https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-34r1.pdf
- NIST Special Publication 800-55 Revision 1, Performance Measurement Guide for Information Security. National Institute of Standards and Technology (U.S. Department of Commerce), 2008-07. https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-55r1.pdf
- NIST Special Publication 800-39, Managing Information Security Risk: Organization, Mission, and Information System View. National Institute of Standards and Technology (U.S. Department of Commerce), 2011-03. https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-39.pdf
- NIST Special Publication 800-50, Building an Information Technology Security Awareness and Training Program. National Institute of Standards and Technology (U.S. Department of Commerce), 2003-10. https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-50.pdf
- NIST Cybersecurity Framework (CSF) 2.0 (NIST.CSWP.29). National Institute of Standards and Technology (U.S. Department of Commerce), 2024-02-26. https://nvlpubs.nist.gov/nistpubs/CSWP/NIST.CSWP.29.pdf
Before you buy
- How do I get it?
- Pay, and the download appears on this page straight away. The links are also emailed to you. No account is required.
- What if it isn't for me?
- Email us within 14 days for a full refund, no questions asked.
- Is there online practice for this exam too?
- No. PrepPass has no online question bank for this exam; the book is self-contained. Its chapter quizzes and full-length practice exam, each question with a worked explanation, are all in the PDF and EPUB.
- Can I read it on my phone?
- Yes — the EPUB is for phones and e-readers, the PDF is for printing and tabbing. You get both.
The details
Written to ISACA's updated CISM exam content outline, in force for exams from 3 November 2026: 233 original questions with worked explanations and a 150-question full-length practice exam.
- Format: PDF + EPUB download · 128 pages
- 233 practice questions in the book, with a full answer key
- $24.99 one-time — no subscription
- 14-day money-back guarantee · refund policy
- Cross-referenced against: ISACA's CISM exam content outline (2026 update) and candidate guide, with NIST CSF 2.0 and SP 800-series publications
- Last updated: September 2026
- Verified from the official source(ISACA's CISM exam content outline (2026 update) and candidate guide, with NIST CSF 2.0 and SP 800-series publications)
- Instant download, yours for life
What the book gives you
PrepPass has no online question bank for this exam, so the $24.99 book is complete in itself: the material taught in order, a quiz closing each chapter and a full-length practice exam, in a file you own.
- Systematic teaching — every exam section explained chapter by chapter, start to finish, not just questions
- Print it & tab it — a paper-ready PDF you can highlight, mark up, and bring to your study table
- Study anywhere, offline — EPUB on your phone or e-reader; no wifi, no browser tabs
- Everything in one place — the chapters and the practice questions in one file
- Yours for life — one-time $24.99, instant download, no subscription
And it's risk-free: 14-day money-back guarantee — not satisfied? Email us for a full refund, no questions asked. See the refund policy.
14-day money-back guarantee · full refund, no questions asked.
One-time purchase, lifetime access to the download. The eBook is the full CISM — Certified Information Security Manager study guide in PDF and EPUB. Educational summary, not professional or legal advice — always confirm the current rules with the official source. Last updated: September 2026.