StudyToCert

All certifications / CISM / Lessons

ISACA Certified Information Security Manager (CISM) 2026 exam content outline · Domain 3: Information security program

Control testing and evaluation

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Controls must be checked to confirm they work. Testing answers two questions: is the control designed to meet its objective (design effectiveness), and does it actually operate as designed over time (operating effectiveness)? A control can be perfectly designed on paper and never performed, or performed faithfully but unable to address the risk. The information security manager needs both answers to know whether residual risk is where management believes it is.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 7 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CISM for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CISM study plan