← CISM overviewCertified Information Security Manager / STUDY TOOLS
Exam coverage map
ISACA changes CISM on November 3, 2026: weights become 18/20/33/29 and enterprise/security architecture receive explicit emphasis. The architecture concepts here help bridge that change; confirm the full revised outline for a later booking. Passing is separate from certification experience and application requirements.
Published objectives
| Objective |
Revision topic |
| 1A · Enterprise governance |
01 Security Leadership, Ethics and Business Risk, 06 Security Strategy, Risk Ownership and Architecture |
| 1B · Security strategy |
06 Security Strategy, Risk Ownership and Architecture |
| 2A · Risk assessment |
02 Governance, Risk and Assurance, 06 Security Strategy, Risk Ownership and Architecture |
| 2B · Risk response and ownership |
02 Governance, Risk and Assurance, 06 Security Strategy, Risk Ownership and Architecture |
| 3A · Program development |
06 Security Strategy, Risk Ownership and Architecture, 07 Security Programs, Suppliers and Useful Metrics |
| 3B · Program management |
03 Security Assessment and Assurance, 07 Security Programs, Suppliers and Useful Metrics |
| 4A · Incident readiness |
04 Incident Response and Evidence, 05 Data Lifecycle, Privacy and Recovery, 08 Incident Leadership, Continuity and Recovery Decisions |
| 4B · Incident operations |
04 Incident Response and Evidence, 08 Incident Leadership, Continuity and Recovery Decisions |