StudyToCert

All certifications / CISM / Lessons

ISACA Certified Information Security Manager (CISM) 2026 exam content outline · Domain 1: Information security governance

Legal, regulatory and contractual requirements

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Every organization operates under external obligations. Laws and regulations, such as data protection laws, sector rules for health or finance, and breach notification requirements, set minimum expectations and carry penalties. Contracts with customers, partners and card brands add more, for example the Payment Card Industry Data Security Standard (PCI DSS) for anyone who stores, processes or transmits payment card data. The information security manager must know which obligations apply and make sure the program addresses them, working closely with legal counsel and compliance rather than interpreting the law alone.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CISM for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CISM study plan