StudyToCert

All certifications / CISM / Lessons

ISACA Certified Information Security Manager (CISM) 2026 exam content outline · Domain 3: Information security program

Program resources: people, processes, tools and technology

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

An information security program is the organized set of activities, resources and controls that carries out the security strategy. It turns intentions into daily work: policies are maintained, access is reviewed, vulnerabilities are fixed, staff are trained and incidents are handled. Building it means deciding what resources are needed and where they come from. CISM expects you to plan resources from the strategy and its risk priorities, not from a wish list of products or a target headcount.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study CISM for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the CISM study plan