← All pathways

CISM

Full depth

ISACA · Blueprint 2022-06-01 · verified 21 September 2026

Management decisions, not technical execution. Gather information, respect ownership, align to the business objective, follow the sequence.

Start free

Membership is free and takes a minute. It is what saves your position, your bands and your plan.

Join free to start Already a member? Sign in

Blueprint

1 Information Security Governance 17%
2 Information Security Risk Management 20%
3 Information Security Program 33%
4 Incident Management 30%

Weightings taken from the owner's published exam outline. Owner's site.

What this pathway contains

160Flashcards

Blueprint-weighted, one idea per card, with the objective each one serves.

574Practice items

A direction-finder, and a check per domain with rationales withheld until you submit.

150Readiness form

Matches the real exam's length. A band is released only under four conditions.

After the exam

The certificate is the start of the job, not the end of it. This exam tests what you know about the subject. The Association's courses cover what the role asks for once the certificate is on the wall, and each one ends in an artefact you keep.

Browse the course catalog