Skip to content
CBT Nuggets
DemoBook a Demo
ISACAProfessional

CISM – Certified Information Security Manager

Standardize your team on CISM – Certified Information Security Manager with a structured ISACA training path — virtual labs and team admin reporting included on every CBT Nuggets training subscription.

1
Course
$575 for members $760 for non-members
Exam cost
4
Core skills
Security operations center analysts monitoring threat dashboards
Difficulty
Difficulty: 4 of 5 (Advanced)
Advanced
Exam cost
$575 for members $760 for non-members
Courses on path
1
Official source
Exam code
  • CISM

Exam datasheet

Exam length
4 hours
Questions
150
Passing score
450 out of 800
Format
Multiple choice questions
Prerequisites
None, but adherence to the ISACA Code of Professional Ethics and the CISM Continuing Education Policy is required
Recommended experience
5 years of work experience in information security management, with at least 3 years of experience in three or more of the CISM content areas
Recertification
3 years
Hiring-market salary
$100,000 - $150,000
Certified professionals
Over 48,000

Public hiring-market data — not a CBT Nuggets guarantee.

Skills your team builds

Information Security GovernanceRisk ManagementInformation Security Program Development and ManagementInformation Security Incident Management

Every certification includes

Expert-led video training
Virtual labs
Certification practice exams
Per-team completion reporting

ISACA career ladder

Where CISM – Certified Information Security Manager sits in your team's ISACA progression

The cert your team is on now, plus the levels above and below. Use this to map an engineer's next-step credential or to plan headcount coverage across tiers.

Compliance coverage

CISM – Certified Information Security Manager on your audit packet

Compliance frameworks CISM – Certified Information Security Manager training is commonly cited against, plus the control families the cert addresses. Use this as a planning aid for the procurement conversation, your SOC 2 / HIPAA / PCI prep packet, or the CMMC self-assessment crosswalk — paired with your auditor’s formal control crosswalk for attestation-grade mapping.

  • FrameworkSOC 2
    Control families
    CC1CC2CC8
  • FrameworkISO 27001
    Control families
    A.5A.6
  • FrameworkNIST 800-53
    Control families
    PMRA

Mappings reflect the cert’s stated learning objectives against published framework control families. Not a formal attestation or substitute for vendor audit guidance — pair with your auditor’s control crosswalk for the official mapping your SOC 2 or HIPAA review requires.

Customer outcome

Make CISM a coverage number your auditor can quote

CISM – Certified Information Security Manager certified engineers are easy to count and easy to prove. CBT Nuggets bundles the prep into a single team playlist so leadership sees who's on the path, who finished, and who's exam-ready — without spreadsheets.

1 path
from foundation to credential — assigned and tracked as one playlist

Coverage proof

Make CISM a number on your team capability sheet, not a single engineer’s certificate.

Standardizing your team on CISM gives leadership and auditors a coverage number they can quote — and gives ISACA incident response a baseline of capability you can predict instead of hoping for.

Credential: CISM – Certified Information Security Manager

Exam
  • CISM

Frequently asked questions about CISM – Certified Information Security Manager training

Common questions IT directors ask when evaluating CISM – Certified Information Security Manager training for their team.

How does CISM – Certified Information Security Manager fit our SOC 2 / ISO 27001 / NIST 800-53 compliance program?

Teams in regulated industries commonly cite CISM – Certified Information Security Manager when documenting training coverage for SOC 2, ISO 27001, NIST 800-53. The specific control families CISM – Certified Information Security Manager maps to depend on your environment and audit scope — see the compliance mapping section above this FAQ for the planning view, and pair it with your auditor's control crosswalk for the formal attestation mapping. Team reporting in CBT Nuggets documents assigned training, completion, and certification coverage for the audit packet your reviewer actually wants to see.

What's the ROI of certifying our team on CISM – Certified Information Security Manager?

IT Directors typically frame CISM – Certified Information Security Manager ROI in operational terms — faster troubleshooting, defensible role coverage, predictable onboarding velocity, and audit-ready training documentation. The metrics that matter aren't seat-time or completion percentages; they're mean time to resolve, time-to-productivity for new ISACA hires, and certification coverage by role.

How does CBT Nuggets CISM – Certified Information Security Manager training compare to Pluralsight, LinkedIn Learning, or Udemy Business?

CBT Nuggets CISM – Certified Information Security Manager courses are built by named expert trainers (not crowd-sourced contributors), include hands-on virtual labs in many courses, and include certification practice exams mapped to the vendor's published exam objectives. Team admin reporting tracks assignment, completion, and exam-readiness per engineer — the surface managers actually use to manage team training programs. See /compare for the full feature comparison.

How do I assign and track CISM – Certified Information Security Manager training for my team?

From the admin console, managers create a training playlist (one or more courses on the CISM – Certified Information Security Manager path), assign it to specific engineers or role groups, and track completion + practice-exam scores per learner. Team-wide reporting rolls up to a single dashboard you can export for monthly leadership reviews or quarterly compliance reporting. No spreadsheet, no per-engineer license fiddling.

How long does it take to certify a team on CISM – Certified Information Security Manager?

Depends on the cert and the team's starting baseline. Entry-level ISACA certs typically run 4–6 weeks per engineer from a cold start; associate-level certs run 8–12 weeks; professional/expert tracks can run 3–6 months. Most teams budget the full quarter for any associate-level certification so engineers have time to actually apply the lab work before the exam.

What if ISACA updates the CISM – Certified Information Security Manager exam objectives?

CBT Nuggets updates ISACA course content as exam objectives refresh — typically within weeks of the vendor's release. When ISACA restructures or renames a track (a common pattern), the assigned training paths stay aligned with the same team training plan; managers don't have to rebuild the playlist from scratch. The training stays current without anyone losing their certification status mid-stream.

Ready to CISM – Certified Information Security Manager-certify your team?

Build CISM – Certified Information Security Manager capability across your team

See how CBT Nuggets helps IT Directors plan and track CISM – Certified Information Security Manager training across the team — labs, practice exams, and reporting included.