All certifications / CISM / Lessons
CISM 2026 exam content outline lessons
Study CISM for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CISM study planA week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Domain 1: Information security governance
- Enterprise governance and the role of the information security manager
- Organizational culture and its effect on security behavior
- Legal, regulatory and contractual requirements
- Organizational structures, roles and responsibilities (board, steering committee, CISO, data owners)
- Information security strategy: current state, desired state and gap analysis
- Governance frameworks and standards: COBIT, ISO/IEC 27001, NIST CSF 2.0
- Strategic planning: business cases, budgets and resource allocation
- Risk appetite, risk tolerance and aligning security with business objectives
Domain 2: Information security risk management
- Emerging risk and the threat landscape
- Vulnerability and control deficiency analysis
- Risk assessment methods: qualitative, quantitative and semi-quantitative
- Risk scenarios, likelihood and impact
- Risk treatment options: mitigate, transfer, avoid, accept
- Risk and control ownership
- Risk registers, key risk indicators and risk monitoring
- Reporting risk to senior management and the board
Domain 3: Information security program
- Program resources: people, processes, tools and technology
- Information asset identification, valuation and classification
- Industry standards and control frameworks for building the program
- Enterprise architecture and information security architecture
- Information security policies, standards, procedures and guidelines
- Information security program metrics: KPIs, KRIs and maturity
- Control design and selection: types, categories and control objectives
- Control implementation, integration and change management
- Control testing and evaluation
- Security awareness and training programs
- Managing external services: vendors, cloud providers and fourth parties
- Program communications and reporting to stakeholders
Domain 4: Incident management
- Incident response plan and incident management team structure
- Business impact analysis: critical processes, RTO, RPO and MTD
- Business continuity plan (BCP) development
- Disaster recovery plan (DRP) and recovery site strategies
- Incident classification, categorization and severity
- Incident management training, testing and exercises
- Incident management tools and techniques: SIEM, SOAR and playbooks
- Incident investigation, evaluation and evidence handling
- Incident containment, eradication and recovery
- Incident communications: escalation, notification and regulatory reporting
- Post-incident review and lessons learned