ISACA / Professional / CISM
Certified Information Security Manager
Turn security risks into accountable decisions, funded programs and coordinated incident response.
ISACA changes CISM on November 3, 2026: weights become 18/20/33/29 and enterprise/security architecture receive explicit emphasis. The architecture concepts here help bridge that change; confirm the full revised outline for a later booking. Passing is separate from certification experience and application requirements.
THE REVISION PATH
Your topics, in order.
Read. Recall. Explain the alternative.
Security Leadership, Ethics and Business Risk
Protect people; understand the business; assign the risk owner.
Governance, Risk and Assurance
Business owns risk; controls reduce it; evidence checks it.
Security Assessment and Assurance
Test the requirement; report the business consequence.
Incident Response and Evidence
Contain harm while preserving what explains it.
Data Lifecycle, Privacy and Recovery
Know the owner, keep only what you need, test restoration.
Security Strategy, Risk Ownership and Architecture
Business sets the destination; security manages the risk on the route.
Security Programs, Suppliers and Useful Metrics
Fund the capability, assign an owner, test the result.
Incident Leadership, Continuity and Recovery Decisions
Prepare authority before the crisis; recover the business, not just servers.
How this guide is organised
Original revision notes arranged around practical decisions. The linked official objectives define the mapped scope; primary documentation supports the explanations. Read each topic, answer without looking, then explain why another option would fail.
- Official exam guide ↗ Scope authority
- ISACA November 2026 change announcement ↗ Version change
Revision material supports preparation; it does not guarantee every possible exam question. Check the exam version and official objectives before booking.