- Domain 1 — Information Security Governance (17%).
- How CISM questions test judgment, stakeholder trade-offs, and “best for the enterprise,” versus technician-first answers.
Certified Information Security Manager (CISM) Certification Training Course
Build the management judgment the CISM exam rewards: aligning security with the business, governing risk, running the program, and leading incident outcomes.
Prepare to own information security—not only operate it.
This Accumentum course is for professionals who own or will own the information security program—security managers, aspiring CISOs, IT leaders, and risk or governance stakeholders—not solely hands-on analysts. Analysts who already operate well at the keyboard can use it to shift into management language, trade-offs, and board-ready decisions. It is not an introductory hacking or tool-tuning class.
Instruction stays on management decisions: who owns the risk, what “adequate” means for this organization, and how you would explain a control or incident choice to leadership. Labs and stories, when used, support that lens.
The ten modules follow the four current ISACA CISM job practice domains. Domain weights are ISACA’s published split for the outline in effect until the 3 November 2026 content update. Confirm the outline that matches your scheduled exam date on ISACA’s CISM exam content outline.
Walk away able to brief governance, run risk, direct the program, and lead incidents as a manager.
Frame security as governance
Explain how strategy, policy, and organizational structure support business objectives—and how you would brief executives on that alignment.
Run a risk conversation that holds up
Identify, analyze, treat, and report information security risk with clear ownership, appetite, and monitoring.
Direct the security program
Select and oversee resources, classification, controls, metrics, awareness, and third-party expectations—not only implement a control yourself.
Lead incident management as a manager
Connect readiness (plans, BIA, continuity, recovery) to response, communication, and post-incident improvement.
Who Should Attend
- Managers accountable for information security strategy, policy, and program results
- Practitioners moving from operations into security leadership
- Governance, risk, and compliance leaders who partner with security
- Teams that need a shared CISM vocabulary across audit, risk, and operations
- A better fit elsewhere: if your goal is hands-on detection, pentest tooling, or auditor-first practice, consider a technical or CISA-oriented path instead of treating CISM as a skills swap.
Prerequisites
- This course assumes you are preparing to own or partner on the information security program, not starting from an introductory technical lab class.
- Earning CISM requires meeting ISACA’s experience and application rules (including information security work experience with a management component, as ISACA defines it, plus CPE after certification). Training does not replace those requirements.
- ISACA allows candidates to take the exam and apply for certification later, within ISACA’s published windows and experience rules. Confirm current policy on ISACA.org; Accumentum cannot waive ISACA requirements.
- When you enroll, confirm which exam content outline your exam date uses (current outline vs. the update effective 3 November 2026).
Ten modules mapped to ISACA’s four CISM domains.
Domain weights below are ISACA’s published split for the outline in effect until the 3 November 2026 content update: Governance 17%, Risk 20%, Program 33%, Incident 30%. Extra time is on the heavier program and incident areas.
CISM as a management exam (Governance)
Strategy, frameworks, and organizational design (Governance)
Risk assessment in context (Risk)
Risk response and reporting (Risk)
Program foundation (Program)
Program operations (Program)
People, partners, and communication (Program)
Incident readiness (Incident)
Response and recovery (Incident)
Integrated scenarios and exam practice (Incident)
- Domain 1 — Information Security Governance (17%).
- Information security strategy, governance structures, culture, and reporting lines that make policy executable.
- Domain 2 — Information Security Risk Management (20%).
- Emerging threats, vulnerability and control-gap analysis, and assessment methods managers use to prioritize.
- Domain 2 — Information Security Risk Management (20%).
- Treatment options, risk and control ownership, appetite, monitoring, and reporting that support decisions rather than status theater.
- Domain 3 — Information Security Program (33%).
- Resources (people, tools, technologies), information asset identification and classification, standards, policies, procedures, guidelines, and program metrics.
- Domain 3 — Information Security Program (33%).
- Control design, selection, implementation, integration, testing, and evaluation—directed as a program owner, not only as an implementer.
- Domain 3 — Information Security Program (33%).
- Awareness and training, management of external services (providers, suppliers, third and fourth parties), and program communications and reporting.
- Domain 4 — Incident Management (30%).
- Incident response plans, business impact analysis, business continuity, disaster recovery, classification, and training/testing of the incident capability.
- Domain 4 — Incident Management (30%).
- Tools and techniques, investigation, containment, communications (reporting, notification, escalation), eradication, recovery, and post-incident review.
- Domain 4 — Incident Management (30%), with cross-domain cases.
- Cross-domain cases that mix governance, risk, program, and incident decisions; pacing and how to read ISACA-style stems. Practice is instructional; it is not a score guarantee.
Management-focused CISM exam preparation with Accumentum.
Management lens
Instruction stays on who owns the risk, what adequate means for this organization, and how you would explain a control or incident choice to leadership.
Four published domains
Ten modules built on ISACA’s four CISM job practice domains, with extra time on the heavier program and incident areas of the current outline.
Exam-format literacy
Public ISACA facts only: 150 multiple-choice items, four hours, scaled 200–800 with a published passing score of 450, computer-based testing.
No invented guarantees
This page does not list pass-rate guarantees, tuition, or cohort dates. Request current enrollment options from Accumentum.
CISM exam format (public ISACA facts).
CISM Exam Readiness
Always re-check facts on ISACA’s CISM pages and candidate materials before you schedule.

Credential: Certified Information Security Manager (CISM), ISACA. Structure: four job practice domains (governance, risk management, information security program, incident management).
Items: 150 questions. Item type: multiple choice; one best answer. Time: four hours. Score: scaled 200–800; 450 is the published passing score. Delivery: computer-based testing (test center and remote options as offered by ISACA’s testing partner).
ISACA has announced a CISM Exam Content Outline update effective 3 November 2026. Confirm the outline that matches your scheduled exam date. Format (question count, duration, scoring scale) is described by ISACA as remaining in the same family of exam; content and domain emphasis can change.
Certification, not just the exam: earning CISM also requires meeting ISACA’s experience and application rules, plus CPE after certification. Training does not replace those requirements. Exam registration fees are set by ISACA and are not Accumentum tuition; they are not listed here because they change.
Public exam facts, audience, and the November 2026 content-outline update—without invented prices, dates, or pass rates.
No. CISM is ISACA’s manager credential. It tests how you govern and run information security, not how you configure a single product. Analysts can take it, but the scoring target is managerial judgment.
People who own or will own the security program: managers, aspiring CISOs, and GRC stakeholders. It is not a pentest class.
No. CISA and CISM share an ISACA style but different jobs: assurance versus security management. Choose based on the role you hold or want.
ISACA allows candidates to take the exam and apply for certification later, within ISACA’s published windows and experience rules. Confirm current policy on ISACA.org; Accumentum cannot waive ISACA requirements.
Yes. The ten modules are built on the four published domains, with extra time on the heavier program and incident areas of the current outline (Governance 17%, Risk 20%, Program 33%, Incident 30%).
Public ISACA facts: 150 multiple-choice questions, four hours, scaled score 200–800 with a published passing score of 450, delivered as computer-based testing.
When you enroll, confirm which outline your exam date uses. Accumentum will align materials to the outline in force; do not assume a 2025/early-2026 workbook matches a post–3 November 2026 sitting.
No. We do not publish pass-rate guarantees, fake tuition, or cohort dates here. Request current enrollment options from Accumentum.
No. Experience and CPE are required by ISACA. Review current rules on ISACA.org.
If you are preparing to manage information security—not only operate it—request enrollment or talk to Accumentum about the Certified Information Security Manager (CISM) Certification Training Course.
Enroll in CISM Certification Training with Accumentum.
If you are preparing to manage information security—not only operate it—start a conversation about CISM training with Accumentum.
Official exam information: ISACA CISM. Exam content outline: ISACA CISM exam content outline.
Prepare to own the information security program.
Request Accumentum CISM training if you are a manager, aspiring CISO, or GRC stakeholder preparing for ISACA’s CISM exam—not a pentest class.
