The Certified Information Security Manager (CISM) is an ISACA credential for people who manage an organization’s security program. ISACA requires five or more years of professional experience across at least three of the four CISM domains, gained within the 10 years before you apply. The exam fee is US$575 for members and US$760 for non-members.
What Is the CISM Certification?
The CISM shows that you can run security as a management function. That’s different from the hands-on work of testing systems or watching alerts. A CISM holder is expected to design a security program, set priorities, manage risk and explain it to people who control budgets.
ISACA, which stands for the Information Systems Audit and Control Association, issues the credential. Our certification data classes it as advanced, in the same tier as the ISC2 CISSP, and well above foundational credentials such as CompTIA Security+.
That placement tells you who it’s for. People earn the CISM after years of work, usually when they’re moving from technical roles into leadership. It isn’t an entry-level credential, and it’s not meant to be.
What Are the CISM Requirements?
ISACA’s requirement is specific. You need five or more years of CISM professional work experience across at least three of the four CISM domains. The experience has to fall within the 10-year period before the application date.
Two details deserve attention. First, the experience has to be spread across domains. Five years in one narrow function won’t meet it. Second, the 10-year window means old experience eventually ages out. If you’ve been in the field a long time, check the dates.
A degree doesn’t replace the experience requirement. That’s different from some other credentials, where a degree can count toward part of the work history. For the CISM, a master’s degree is useful preparation, but the five years still have to come from work.
How Much Does the CISM Cost?
ISACA lists the exam fee at US$575 for members and US$760 for non-members. The difference is US$185, so it’s worth checking what ISACA membership costs before you decide which fee to pay.
Other costs add up. Preparation materials, courses and practice questions vary by provider, and employers often cover some of them. If your company has a training budget, ask about it before you pay out of pocket.
Renewal is a cost of time more than money. ISACA requires a minimum of 120 continuing professional development (CPE) hours during a three-year reporting period, with a minimum of 20 hours each year. That averages 40 hours a year, and many people meet it through conferences, courses and work-related learning.
How Does the CISM Exam Work?
ISACA says the exam is computer-based. You can take it at an authorized PSI testing center or as a remotely proctored exam.
That flexibility is helpful if you live far from a testing center or have a demanding schedule. Remote proctoring lets you sit the exam at home or at work, though you’ll need to meet the technical and room requirements ISACA sets.
Because exam details change, check ISACA’s page for the current number of questions, time limit and passing score before you register.
Who Should Pursue the CISM?
The CISM suits people already doing or heading toward security management. Typical candidates include senior analysts who lead investigations, security engineers who’ve started managing people, and IT managers who’ve taken over security duties.
If you’re still building technical skills, a different credential fits better. CompTIA Security+ is the foundational choice, and our CEH guide covers a hands-on option. Come back to the CISM when you have the experience ISACA asks for.
If you’re coming from a compliance or risk background, the CISM may fit sooner than you’d expect, since the credential is about governance and risk as much as technology. Our online cybersecurity policy and law degrees list shows programs that build on that background.
What Does a Security Manager Earn?
The federal wage survey doesn’t have a category for security managers. The closest match is computer and information systems managers, which includes security leaders along with other IT managers. The May 2025 median is $175,140 a year, and the mean is $192,160.
The spread is wide. A quarter of these managers earn $138,060 or less and a quarter earn $220,730 or more. The lowest-paid tenth earn $107,550 or less and the highest-paid tenth earn $297,510 or more.
BLS projects 16 percent employment growth for the group from 2025 to 2035, with about 53,500 openings a year. It lists a bachelor’s degree as typical entry education, but managers also need work experience, which is the reason the CISM asks for so much of it.
For comparison, information security analysts have a median of $129,180. The step from analyst to manager is where the pay gap shows up. Our can you make $200,000 in cybersecurity guide walks through it.
Which Online Master’s Programs Prepare You for the CISM?
Four programs we compare name CISM preparation, and all four are master’s degrees with a management or risk focus.
American National University’s M.S. in cybersecurity lists electives aligned to CISSP, CISM, CSSLP, CEH and other certification topics. It requires a 50-hour practicum each term, and its published total tuition of $23,016 includes fees, textbooks and lab equipment.
Saint Mary’s University of Minnesota embeds graduate certificates in Cybersecurity Management and Cybersecurity Technology and lists direct preparation for CySA+, Security+, Network+ and CISSP and CISM. It has six start dates a year and doesn’t require the GRE.
The University of New Haven’s M.S. in cyber risk management is asynchronous and lists CISM and CISSP preparation. It also offers a 50 percent tuition discount to public safety personnel.
West Virginia University’s M.S. in business cybersecurity management covers material for eleven industry certifications, includes official CISSP training through ISC2, and ends with a capstone on a live project with a corporate partner.
Is the CISM Worth the Cost?
Weigh the cost against the role you’re aiming for. The exam fee of US$575 for members or US$760 for non-members is small next to the pay gap between analysts and managers. The median for information security analysts is $129,180, and the median for computer and information systems managers is $175,140.
The credential doesn’t cause that gap. The managers in the survey earned their pay through experience, leadership and scope. But employers hiring for security management often look for proof that a candidate understands governance and risk, and the CISM is a recognized way to show it.
The larger cost is time. Five years of experience, preparation and 120 hours of renewal learning every three years add up. If your employer pays for training, the math improves. If you’re paying yourself, plan around the real timeline, not the exam date.
One more point: the credential travels. ISACA is a global body, and a CISM you earn at one employer goes with you to the next. That portability is part of why people who change jobs often keep renewing it.
How Can You Show Management Skills Before You Qualify?
You don’t have to wait five years to look like a future manager. Start with the work in front of you. Volunteer to write a policy, run a risk assessment or brief leadership after an incident. Each of those is a management task, and each counts as a story in an interview.
Capstones can help too. West Virginia University’s program ends with a live cybersecurity project for a corporate partner. The University of New Haven’s ends with a Cybersecurity Strategic Planning Capstone. Franklin University’s final course is a Security Research and Capstone that produces an original paper and presentation on a current information security topic.
Those projects give you something concrete to describe. They aren’t a substitute for the work history ISACA requires, but they show you can think like a manager while you build it.
How Do CISM and CISSP Differ?
People often confuse the two, and the difference matters for your plan.
The CISM is a management credential. It’s built around running a security program and managing risk. The CISSP is broad and technical-to-managerial. ISC2 requires five years of cumulative full-time experience in two or more of its eight domains, and a degree can satisfy up to one year of it. Our CISSP requirements guide covers the details.
Many senior security professionals hold both. If you have to choose one, look at the job you want. A role titled security manager or director often values the CISM. A role centered on architecture or engineering often values the CISSP.
Experience rules differ too. The CISM asks for experience across at least three of four domains within a 10-year window. The CISSP asks for experience in two or more of eight domains and lets you pass first and earn the experience later as an Associate of ISC2.
What Should You Study If You’re Aiming for Security Management?
A management-focused degree helps because it teaches the language of budgets, risk and governance. Look for courses in risk management, policy and compliance, security program planning and leadership.
Franklin University’s M.S. in cybersecurity lists Information Risk Management and Information Security Policy and Governance among its courses, and it credits prior learning from credentials such as CRISC. The University of New Haven’s program centers on a Cybersecurity Strategic Planning Capstone and Leadership and Team Building.
Our online cybersecurity management degrees list shows programs with a business or leadership focus, and our online master’s in cybersecurity list covers the full set.
How Should You Plan the Path to CISM?
Think in stages. Early on, build technical and operational experience. That means monitoring, incident response, risk assessments and policy work. Aim to touch more than one area, since the CISM asks for experience in at least three domains.
Midway, add a master’s degree if it fits your plans. Programs such as those above teach management skills while you keep working. Choose an asynchronous or part-time format if you can’t step away from your job.
Later, apply when you meet the five-year rule. Gather your work history, confirm the dates fall within 10 years and check the domains. Then choose your fee tier, schedule the exam and plan how you’ll earn your 120 renewal hours.
The sequence isn’t glamorous, but it’s reliable. People who plan their experience around the requirement tend to reach the credential faster than people who try to catch up afterward.
What Are the Limits of the CISM?
The credential doesn’t make you a manager. Employers promote people for judgment, communication and results, and the CISM is one supporting piece of evidence.
It also isn’t the best match for every security job. If your work is hands-on testing or engineering, a technical credential may serve you better. And the experience requirement means it can’t be earned straight out of school.
Finally, the cost in time is real. The renewal rule asks for 120 hours of learning over three years, so you’re committing to ongoing study. That’s valuable if you want to stay current, and a burden if you don’t.
Frequently Asked Questions
What Is the CISM Certification?
What Are the CISM Requirements?
How Much Does the CISM Exam Cost?
How Do You Keep the CISM Active?
How Do You Take the CISM Exam?
Which Online Degrees Prepare You for the CISM?
Sources
- Get CISM Certified
- CISM Certification Overview
- Occupational Outlook Handbook: Computer and Information Systems Managers
All sources retrieved .