- Domain 1 — Information Security Governance (17%).
- How CISM questions test judgment, stakeholder trade-offs, and “best for the enterprise,” versus technician-first answers.
Build the management judgment the CISM exam rewards: aligning security with the business, governing risk, running the program, and leading incident outcomes.
This Accumentum course is for professionals who own or will own the information security program—security managers, aspiring CISOs, IT leaders, and risk or governance stakeholders—not solely hands-on analysts. Analysts who already operate well at the keyboard can use it to shift into management language, trade-offs, and board-ready decisions. It is not an introductory hacking or tool-tuning class.
Instruction stays on management decisions: who owns the risk, what “adequate” means for this organization, and how you would explain a control or incident choice to leadership. Labs and stories, when used, support that lens.
The ten modules follow the four current ISACA CISM job practice domains. Domain weights are ISACA’s published split for the outline in effect until the 3 November 2026 content update. Confirm the outline that matches your scheduled exam date on ISACA’s CISM exam content outline.
Explain how strategy, policy, and organizational structure support business objectives—and how you would brief executives on that alignment.
Identify, analyze, treat, and report information security risk with clear ownership, appetite, and monitoring.
Select and oversee resources, classification, controls, metrics, awareness, and third-party expectations—not only implement a control yourself.
Connect readiness (plans, BIA, continuity, recovery) to response, communication, and post-incident improvement.
Domain weights below are ISACA’s published split for the outline in effect until the 3 November 2026 content update: Governance 17%, Risk 20%, Program 33%, Incident 30%. Extra time is on the heavier program and incident areas.
Instruction stays on who owns the risk, what adequate means for this organization, and how you would explain a control or incident choice to leadership.
Ten modules built on ISACA’s four CISM job practice domains, with extra time on the heavier program and incident areas of the current outline.
Public ISACA facts only: 150 multiple-choice items, four hours, scaled 200–800 with a published passing score of 450, computer-based testing.
This page does not list pass-rate guarantees, tuition, or cohort dates. Request current enrollment options from Accumentum.
Always re-check facts on ISACA’s CISM pages and candidate materials before you schedule.

Credential: Certified Information Security Manager (CISM), ISACA. Structure: four job practice domains (governance, risk management, information security program, incident management).
Items: 150 questions. Item type: multiple choice; one best answer. Time: four hours. Score: scaled 200–800; 450 is the published passing score. Delivery: computer-based testing (test center and remote options as offered by ISACA’s testing partner).
ISACA has announced a CISM Exam Content Outline update effective 3 November 2026. Confirm the outline that matches your scheduled exam date. Format (question count, duration, scoring scale) is described by ISACA as remaining in the same family of exam; content and domain emphasis can change.
Certification, not just the exam: earning CISM also requires meeting ISACA’s experience and application rules, plus CPE after certification. Training does not replace those requirements. Exam registration fees are set by ISACA and are not Accumentum tuition; they are not listed here because they change.
Public exam facts, audience, and the November 2026 content-outline update—without invented prices, dates, or pass rates.
No. CISM is ISACA’s manager credential. It tests how you govern and run information security, not how you configure a single product. Analysts can take it, but the scoring target is managerial judgment.
People who own or will own the security program: managers, aspiring CISOs, and GRC stakeholders. It is not a pentest class.
No. CISA and CISM share an ISACA style but different jobs: assurance versus security management. Choose based on the role you hold or want.
ISACA allows candidates to take the exam and apply for certification later, within ISACA’s published windows and experience rules. Confirm current policy on ISACA.org; Accumentum cannot waive ISACA requirements.
Yes. The ten modules are built on the four published domains, with extra time on the heavier program and incident areas of the current outline (Governance 17%, Risk 20%, Program 33%, Incident 30%).
Public ISACA facts: 150 multiple-choice questions, four hours, scaled score 200–800 with a published passing score of 450, delivered as computer-based testing.
When you enroll, confirm which outline your exam date uses. Accumentum will align materials to the outline in force; do not assume a 2025/early-2026 workbook matches a post–3 November 2026 sitting.
No. We do not publish pass-rate guarantees, fake tuition, or cohort dates here. Request current enrollment options from Accumentum.
No. Experience and CPE are required by ISACA. Review current rules on ISACA.org.
If you are preparing to manage information security—not only operate it—request enrollment or talk to Accumentum about the Certified Information Security Manager (CISM) Certification Training Course.
If you are preparing to manage information security—not only operate it—start a conversation about CISM training with Accumentum.
Official exam information: ISACA CISM. Exam content outline: ISACA CISM exam content outline.
Request Accumentum CISM training if you are a manager, aspiring CISO, or GRC stakeholder preparing for ISACA’s CISM exam—not a pentest class.