Global CISM preparation · live online

Live Online CISM Exam Preparation for Information Security Professionals

Prepare for the Certified Information Security Manager (CISM) credential through live online training, recordings, self-paced reinforcement, an AI-supported LMS, 3,000+ practice and revision resources, mock exams and structured guidance for professionals worldwide. EduDelphi provides independent exam preparation; ISACA controls official registration, assessment, results and certification.

40+ hourslive guided CISM preparation
3,000+practice and revision resources
4 domainscurrent CISM exam structure
Live + flexiblerecordings and self-paced support
View CISM Syllabus
Important 2026 update

CISM Exam Update: Which Syllabus Should You Study?

ISACA’s updated CISM Exam Content Outline takes effect on 3 November 2026. Updated official preparation materials are expected in September 2026, and ISACA states that purchasing current official material does not automatically provide access to the replacement version.

Exam before 3 November

Current-outline preparation

Use the current four-domain outline, current notes, question practice and mock strategy for the examination date you have booked.

Exam from 3 November

Updated-outline preparation

Before enrolment, EduDelphi will confirm that your cohort, study notes and practice resources match the updated exam outline for your intended test date.

Planning to test after 3 November? Do not rely on a pre-update study plan. Confirm the applicable materials version, batch timing and official outline before you enrol. Post-update weights will be added only when ISACA publishes the final official outline. Read the detailed CISM exam-format and November-update guide.
CISM at a glance

Know the official CISM route before you plan your preparation

CISM is an information-security-management credential administered by ISACA. Passing the exam is one step; certification also requires the applicable experience, application and maintenance obligations.

150current multiple-choice questions
4 hourscurrent official duration
450current scaled passing score
6 monthsexam eligibility after registration
CISM vs ISACA: CISM is the Certified Information Security Manager credential. ISACA administers the official examination and certification pathway. EduDelphi supports candidates with independent teaching, practice, revision and study planning.

Live online CISM training workshop for information security professionals

Who should take CISM?

Choose CISM when you want broader information-security-management responsibility

CISM is designed around governance, risk, security-programme and incident-management judgement, rather than purely technical implementation tasks.

Governance

Security and GRC leaders

For professionals who align security decisions with enterprise goals, obligations, budgets and accountability.

Risk

IT-risk and assurance professionals

For people who assess threats, communicate risk and shape security-control decisions.

Programme

Emerging security managers

For professionals moving from operational contribution toward security-programme ownership.

When another route may fit better: CISA is more audit and assurance-led, while CISSP is broader technical-security architecture and engineering. Compare CISA and CISM by career fit.

What you receive

What Is Included in EduDelphi Online CISM Training?

A commercial learning system for working professionals: live explanation, practical context, flexible reinforcement and structured exam preparation.

Live teaching

40+ guided hours

Faculty-led domain teaching, scenario discussion, question debriefs and revision planning.

Practice

3,000+ resources

Practice questions, answer explanations, mock exams, revision drills and weak-area support.

LMS support

Learn between sessions

Recordings, notes, mind maps, infographics, podcasts and AI-assisted revision features where applicable.

Flexible route

Live or self-paced support

Recordings and self-paced reinforcement for professionals unable to commit to fixed class times.

Extra guidance

One-to-one support

Discuss a more focused route where additional question, revision or study-planning support is needed.

Team learning

Corporate CISM training

Private cohorts for security, technology, audit, risk and controls teams across time zones.

Current CISM syllabus

CISM Syllabus: Four Information Security Management Domains

The following current structure applies to examinations before the ISACA update effective 3 November 2026. The percentages describe the current exam allocation, not separate passing scores.

Information Security Governance — 17%
  • Enterprise governance, culture, roles and responsibilities.
  • Legal, regulatory and contractual requirements.
  • Security strategy, governance frameworks, standards, resources and business cases.
Information Security Risk Management — 20%
  • Emerging risk and threat landscape.
  • Vulnerability and control-deficiency analysis.
  • Risk assessment, treatment, ownership, monitoring and reporting.
Information Security Program — 33%
  • Programme resources, asset classification, policies, metrics and frameworks.
  • Control design, implementation and testing.
  • Awareness, communications, external-service and programme-management decisions.
Incident Management — 30%
  • Incident readiness, business-impact analysis, continuity and recovery planning.
  • Classification, investigation, containment, communication and recovery.
  • Post-incident review, lessons learned and continuous improvement.
EduDelphi Exam Strategy & Mock Rehearsal
Question debriefs focus on management rationale: what the security leader should do first, who owns the decision, what evidence matters and how to balance business, risk and control objectives. This is EduDelphi preparation methodology, not an official fifth CISM domain.
Practical management learning

Learn the security decision behind the scenario

CISM questions reward management judgement. Our practical discussions move beyond remembering a framework name toward deciding what should happen first and why.

Example: A material security-control weakness appears during a major business rollout. Learners discuss the governance decision, risk ownership, evidence required, escalation route, immediate treatment options and how follow-up should be monitored.
  • Separate a technical symptom from the business-risk decision.
  • Identify the accountable owner and the appropriate management response.
  • Connect control design, reporting and post-incident learning.

Information security manager leading a security governance meeting

Official CISM route

CISM Exam Format, Eligibility, Fees & Certification Process

Current official reference What candidates should plan for
Exam format 150 multiple-choice questions delivered by computer.
Duration and score 4 hours; current passing score is 450 on ISACA’s scaled-score system, not a simple 45% threshold.
Delivery Authorized PSI test centres globally or remote-proctored examination, subject to ISACA rules and availability.
Registration and scheduling Continuous registration. ISACA currently says an appointment can be scheduled as early as 48 hours after payment, with eligibility valid for six months.
Certification Pass the exam, meet the applicable work-experience requirement, submit the application and agree to the ethics and CPE policies. Candidates currently have five years after passing to apply.

CISM exam vs CISM certification

Know which requirement applies when

Take training No formal experience prerequisite.
Take the exam Open to interested candidates.
Pass the exam Current scaled passing score: 450.
Become certified Five or more years of professional information-security-management experience.
Domain coverage Experience across at least three of the four CISM domains.
Experience recency Within the 10 years preceding the certification application.
Application deadline Within five years after passing the exam.

Eligibility

Preparation is not certification eligibility

Candidates can prepare and take the exam before completing every certification condition. Certain ISACA-approved experience substitutions may apply; confirm the current official substitution rules before relying on a waiver. ISACA makes the final determination.

Check current official CISM certification requirements.

Official fee reference

US$575 / US$760 exam

ISACA currently lists US$575 for members and US$760 for non-members, plus a US$50 certification-application processing fee. Membership, taxes, resits and later maintenance can change the final total.

CISM Exam Booking at a Glance: Registration is continuous; eligibility lasts six months; appointments can be scheduled from 48 hours after payment; availability is typically shown up to 90 days ahead; and rescheduling is currently penalty-free when completed at least 48 hours before the appointment. PSI test-centre and remote-proctored options remain subject to current ISACA availability and rules.
Career relevance

Where Can CISM Support Your Security-Management Career?

CISM preparation supports the governance, risk, programme and incident-management capability expected in leadership-oriented security roles. Outcomes depend on experience, employer and market; this is not a salary promise.

Information Security ManagerGRC ManagerSecurity Programme ManagerIT Risk ManagerSecurity Governance LeadIncident Management LeaderSecurity ConsultantRisk & Controls ProfessionalCISO-track professional
Compare the route

CISM vs CISA vs CISSP vs CRISC: Which Credential Fits Your Role?

Route Primary focus Best fit when
CISM Information-security governance, programme, risk and incident management. You are moving toward security-management responsibility.
CISA IT audit, assurance, controls and governance. Audit and assurance are your primary role.
CISSP Broad security architecture, engineering and operations. You need wider technical-security depth.
CRISC IT risk identification, assessment and control. IT-risk and control design are central to your work.
Faculty

Preparation Led by Practical Security and Controls Expertise

Kashif Akhtar, CISM faculty

CISM faculty

Kashif Akhtar

Kashif helps candidates connect CISM domains to governance decisions, technology risk, controls, programme planning and incident readiness. His approach focuses on the management rationale behind each decision, not just answer memorisation.

Faculty insight: Strong candidates do not only identify a control or framework. They decide what an information-security manager should prioritise, who should own the decision and what evidence should guide the next action.
Corporate CISM training

Corporate CISM Training for Global Security, Risk and Technology Teams

A private cohort helps teams develop shared management language around security governance, risk, controls, programme design and incident readiness while creating an organised individual exam-preparation route.

1. Needs mapping

Start with the real team context

Discuss roles, current knowledge, intended CISM journey and relevant security, audit or control context.

2. Cohort design

Plan the delivery model

Set global time zones, pacing, live sessions, recordings where agreed and practical examples.

3. Practice & visibility

Keep preparation organised

Use question checkpoints, mock planning and attendance or progress visibility where agreed for the cohort.

FAQs

CISM Course Questions from Global Candidates

What is CISM certification?
CISM is the Certified Information Security Manager credential administered by ISACA. It validates knowledge across security governance, risk management, security-programme management and incident management.
How many questions are on the CISM exam?
The current CISM exam has 150 multiple-choice questions and a four-hour time limit. The content outline changes on 3 November 2026, so use resources that match your intended exam date.
What is the CISM passing score?
ISACA currently reports a scaled passing score of 450. It should not be interpreted as a percentage-correct threshold.
Can I take CISM online?
ISACA currently offers CISM through authorized PSI test centres and remote-proctored delivery, subject to its current rules, technical requirements and availability.
How much does CISM cost?
ISACA currently lists US$575 for members and US$760 for non-members for the exam, plus a US$50 certification-application processing fee. EduDelphi training is separate and supplied on request.
How long does CISM preparation take?
Timing varies by experience, weekly capacity and target date. EduDelphi provides 40+ guided hours plus recordings, LMS support and flexible revision resources, allowing candidates to build a practical plan around professional commitments.
Do I need experience before taking CISM?
Exam preparation and certification eligibility are different. ISACA makes the final assessment of the experience requirement and applicable substitutions when you apply for certification.
What changes on 3 November 2026?
ISACA has announced an updated CISM Exam Content Outline effective 3 November 2026. Candidates testing after that date should use current post-update resources and planning.
Is the course live or self-paced?
EduDelphi offers live online teaching with recordings and self-paced reinforcement. A recording-led route can be discussed where fixed live timings are not suitable.
What is included in EduDelphi CISM training?
Support includes live guided training, recordings, self-paced reinforcement, an AI-supported LMS, 3,000+ practice and revision resources, mock exams, question support and options for one-to-one or corporate delivery.
Can companies arrange corporate CISM training?
Yes. Global teams can discuss a private cohort with time-zone-aware delivery, practical security-management cases, mock planning and agreed progress support.
How do I maintain the CISM credential?
ISACA currently requires a minimum of 20 CPE hours each year and 120 CPE hours during each three-year reporting period. The current annual maintenance fee is US$45 for ISACA members and US$85 for non-members, alongside ethics and audit-compliance requirements. Review ISACA’s current CISM maintenance policy.
Get course details

Get CISM Fees, Syllabus & a Global Batch Recommendation

Share your country, preferred learning mode and study timeline. We will send current EduDelphi training options, fee guidance, package inclusions, batch recommendations and a clear explanation of the separate official ISACA process.

We respect your privacy. No spam – only relevant course information.

Country-specific guidance

Looking for CISM Training in Your Country?

Explore country-specific CISM guidance for local delivery context and regional course support.

CISM and Certified Information Security Manager are registered trademarks of ISACA. EduDelphi provides independent exam preparation and does not award the credential.