Live Online CISM Exam Preparation for Information Security Professionals
Prepare for the Certified Information Security Manager (CISM) credential through live online training, recordings, self-paced reinforcement, an AI-supported LMS, 3,000+ practice and revision resources, mock exams and structured guidance for professionals worldwide. EduDelphi provides independent exam preparation; ISACA controls official registration, assessment, results and certification.
CISM Exam Update: Which Syllabus Should You Study?
ISACA’s updated CISM Exam Content Outline takes effect on 3 November 2026. Updated official preparation materials are expected in September 2026, and ISACA states that purchasing current official material does not automatically provide access to the replacement version.
Exam before 3 November
Current-outline preparation
Use the current four-domain outline, current notes, question practice and mock strategy for the examination date you have booked.
Exam from 3 November
Updated-outline preparation
Before enrolment, EduDelphi will confirm that your cohort, study notes and practice resources match the updated exam outline for your intended test date.
Know the official CISM route before you plan your preparation
CISM is an information-security-management credential administered by ISACA. Passing the exam is one step; certification also requires the applicable experience, application and maintenance obligations.

Choose CISM when you want broader information-security-management responsibility
CISM is designed around governance, risk, security-programme and incident-management judgement, rather than purely technical implementation tasks.
Governance
Security and GRC leaders
For professionals who align security decisions with enterprise goals, obligations, budgets and accountability.
Risk
IT-risk and assurance professionals
For people who assess threats, communicate risk and shape security-control decisions.
Programme
Emerging security managers
For professionals moving from operational contribution toward security-programme ownership.
When another route may fit better: CISA is more audit and assurance-led, while CISSP is broader technical-security architecture and engineering. Compare CISA and CISM by career fit.
What Is Included in EduDelphi Online CISM Training?
A commercial learning system for working professionals: live explanation, practical context, flexible reinforcement and structured exam preparation.
Live teaching
40+ guided hours
Faculty-led domain teaching, scenario discussion, question debriefs and revision planning.
Practice
3,000+ resources
Practice questions, answer explanations, mock exams, revision drills and weak-area support.
LMS support
Learn between sessions
Recordings, notes, mind maps, infographics, podcasts and AI-assisted revision features where applicable.
Flexible route
Live or self-paced support
Recordings and self-paced reinforcement for professionals unable to commit to fixed class times.
Extra guidance
One-to-one support
Discuss a more focused route where additional question, revision or study-planning support is needed.
Team learning
Corporate CISM training
Private cohorts for security, technology, audit, risk and controls teams across time zones.
CISM Syllabus: Four Information Security Management Domains
The following current structure applies to examinations before the ISACA update effective 3 November 2026. The percentages describe the current exam allocation, not separate passing scores.
Information Security Governance — 17%
- Enterprise governance, culture, roles and responsibilities.
- Legal, regulatory and contractual requirements.
- Security strategy, governance frameworks, standards, resources and business cases.
Information Security Risk Management — 20%
- Emerging risk and threat landscape.
- Vulnerability and control-deficiency analysis.
- Risk assessment, treatment, ownership, monitoring and reporting.
Information Security Program — 33%
- Programme resources, asset classification, policies, metrics and frameworks.
- Control design, implementation and testing.
- Awareness, communications, external-service and programme-management decisions.
Incident Management — 30%
- Incident readiness, business-impact analysis, continuity and recovery planning.
- Classification, investigation, containment, communication and recovery.
- Post-incident review, lessons learned and continuous improvement.
EduDelphi Exam Strategy & Mock Rehearsal
Learn the security decision behind the scenario
CISM questions reward management judgement. Our practical discussions move beyond remembering a framework name toward deciding what should happen first and why.
- Separate a technical symptom from the business-risk decision.
- Identify the accountable owner and the appropriate management response.
- Connect control design, reporting and post-incident learning.

CISM Exam Format, Eligibility, Fees & Certification Process
| Current official reference | What candidates should plan for |
|---|---|
| Exam format | 150 multiple-choice questions delivered by computer. |
| Duration and score | 4 hours; current passing score is 450 on ISACA’s scaled-score system, not a simple 45% threshold. |
| Delivery | Authorized PSI test centres globally or remote-proctored examination, subject to ISACA rules and availability. |
| Registration and scheduling | Continuous registration. ISACA currently says an appointment can be scheduled as early as 48 hours after payment, with eligibility valid for six months. |
| Certification | Pass the exam, meet the applicable work-experience requirement, submit the application and agree to the ethics and CPE policies. Candidates currently have five years after passing to apply. |
CISM exam vs CISM certification
Know which requirement applies when
| Take training | No formal experience prerequisite. |
| Take the exam | Open to interested candidates. |
| Pass the exam | Current scaled passing score: 450. |
| Become certified | Five or more years of professional information-security-management experience. |
| Domain coverage | Experience across at least three of the four CISM domains. |
| Experience recency | Within the 10 years preceding the certification application. |
| Application deadline | Within five years after passing the exam. |
Eligibility
Preparation is not certification eligibility
Candidates can prepare and take the exam before completing every certification condition. Certain ISACA-approved experience substitutions may apply; confirm the current official substitution rules before relying on a waiver. ISACA makes the final determination.
Official fee reference
US$575 / US$760 exam
ISACA currently lists US$575 for members and US$760 for non-members, plus a US$50 certification-application processing fee. Membership, taxes, resits and later maintenance can change the final total.
Where Can CISM Support Your Security-Management Career?
CISM preparation supports the governance, risk, programme and incident-management capability expected in leadership-oriented security roles. Outcomes depend on experience, employer and market; this is not a salary promise.
CISM vs CISA vs CISSP vs CRISC: Which Credential Fits Your Role?
| Route | Primary focus | Best fit when |
|---|---|---|
| CISM | Information-security governance, programme, risk and incident management. | You are moving toward security-management responsibility. |
| CISA | IT audit, assurance, controls and governance. | Audit and assurance are your primary role. |
| CISSP | Broad security architecture, engineering and operations. | You need wider technical-security depth. |
| CRISC | IT risk identification, assessment and control. | IT-risk and control design are central to your work. |
Preparation Led by Practical Security and Controls Expertise
CISM faculty
Kashif Akhtar
Kashif helps candidates connect CISM domains to governance decisions, technology risk, controls, programme planning and incident readiness. His approach focuses on the management rationale behind each decision, not just answer memorisation.
Corporate CISM Training for Global Security, Risk and Technology Teams
A private cohort helps teams develop shared management language around security governance, risk, controls, programme design and incident readiness while creating an organised individual exam-preparation route.
1. Needs mapping
Start with the real team context
Discuss roles, current knowledge, intended CISM journey and relevant security, audit or control context.
2. Cohort design
Plan the delivery model
Set global time zones, pacing, live sessions, recordings where agreed and practical examples.
3. Practice & visibility
Keep preparation organised
Use question checkpoints, mock planning and attendance or progress visibility where agreed for the cohort.
CISM Course Questions from Global Candidates
What is CISM certification?
How many questions are on the CISM exam?
What is the CISM passing score?
Can I take CISM online?
How much does CISM cost?
How long does CISM preparation take?
Do I need experience before taking CISM?
What changes on 3 November 2026?
Is the course live or self-paced?
What is included in EduDelphi CISM training?
Can companies arrange corporate CISM training?
How do I maintain the CISM credential?
Get CISM Fees, Syllabus & a Global Batch Recommendation
Share your country, preferred learning mode and study timeline. We will send current EduDelphi training options, fee guidance, package inclusions, batch recommendations and a clear explanation of the separate official ISACA process.
Looking for CISM Training in Your Country?
Explore country-specific CISM guidance for local delivery context and regional course support.
CISM and Certified Information Security Manager are registered trademarks of ISACA. EduDelphi provides independent exam preparation and does not award the credential.





















