← Home
ISACA · Full exam outline

CISM

Certified Information Security Manager

Security management / CISO trackCore certification
1Information Security Governance17%
1.1Enterprise governance and organizational culture
1.2Legal, regulatory and contractual requirements
1.3Information security strategy development
1.4Strategy resources, budget and metrics
2Information Security Risk Management20%
2.1Emerging risk and the threat landscape
2.2Vulnerability and control deficiency analysis
2.3Risk assessment and analysis
2.4Risk treatment, monitoring and reporting
3Information Security Program33%
3.1Programme resources and asset classification
3.2Industry standards and frameworks
3.3Security control design, selection and implementation
3.4Security awareness training and communication
3.5Third-party service management
3.6Programme metrics and reporting
4Incident Management30%
4.1Incident response plan and business impact analysis
4.2Incident classification and readiness
4.3Incident detection, investigation and containment
4.4Eradication, recovery and post-incident review
4.5Business continuity and disaster recovery
Weights are the certification body’s published values and are checked against each outline revision.