The 4 CISM Domains Explained (With Official Weights)

The four CISM domains and their exam weights: 17, 20, 33, and 30 percent

The CISM exam has four domains: Information Security Governance (17%), Information Security Risk Management (20%), Information Security Program (33%), and Incident Management (30%). Those weights come from the ISACA CISM Examination Content Outline effective 2022, which is the outline in force for exams taken before November 3, 2026.

The number that should shape your plan is 63. Domains 3 and 4 are 63% of the exam between them, which on a 150-question paper works out to roughly 95 questions, against about 55 for Domains 1 and 2 combined. This post walks each domain: what it contains, the question the exam is really asking, the traps, and where your study hours belong.

What are the CISM domain weights?

Domain Name Weight Approx. questions
1 Information Security Governance 17% ~25
2 Information Security Risk Management 20% ~30
3 Information Security Program 33% ~50
4 Incident Management 30% ~45

The exam is 150 multiple-choice questions in 4 hours, scored on a scale of 200 to 800 with 450 to pass. There is no per-domain minimum, so a point in Domain 3 is worth exactly as much as a point in Domain 1. For the full picture on format, fees, and the experience requirement, start with what the CISM exam is.

One framing point before the tour. Every domain below is written from the manager's seat: what needs to happen, who owns it, and what leadership needs to be told. When two options are both technically true, the one a manager would choose wins.

Domain 1: Information Security Governance (17%)

Domain 1 is the foundation the other three are built on. It starts with the split between governance and management, then covers the organizational machinery that makes security work or fail: culture, the security steering committee, the reporting line for the security function, and the roles that come up constantly in stems. Board, executive sponsor, data owner, data custodian, control owner, risk owner. It also covers the external obligations that set your compliance baseline, and the strategy work: desired state, measured gap, roadmap, business case. The frameworks CISM expects you to know at a decision level live here too: COBIT, ISO/IEC 27001 and 27002, and the NIST Cybersecurity Framework.

Governance sets direction and holds people accountable. Management executes. The board can delegate authority to act, but it cannot delegate accountability. Once that split is solid, a large share of Domain 1 questions become "who owns this decision" questions with one obvious answer.

The manager-lens question the exam is asking: does this decision belong to leadership, or to you?

Two named traps. The first is confusing a policy with a standard or a procedure. A policy is mandatory intent approved by senior leadership; a standard is a mandatory specific; a procedure is the steps; a guideline is advice. Plenty of questions are decided purely on which of those the scenario describes. The second is reading the security strategy as a technology roadmap. A CISM strategy starts from a desired state expressed in business terms and a measured gap, and the business case argues in those same terms, so options reasoning from control coverage lose to options reasoning from business objectives.

Study time: about a fifth of your hours, which is more than the 17% weight suggests, and worth every minute for reasons covered further down.

Domain 2: Information Security Risk Management (20%)

Domain 2 is risk, in two halves. Assessment is where the exam tests vocabulary precisely: asset, threat, vulnerability, likelihood, impact, inherent risk, residual risk, risk appetite, risk tolerance. It also covers monitoring the threat environment for events that should trigger a reassessment, telling a vulnerability apart from a control deficiency, and the analysis methods, qualitative through quantitative, including single loss expectancy, annual rate of occurrence, and annualized loss expectancy. Response is the shorter half: the four treatment options of mitigate, transfer, avoid and accept, risk and control ownership, the risk register, and reporting through key risk indicators.

The whole domain rests on one idea: the business owns the risk, and you own the process. You facilitate the assessment, you maintain the register, you report when a threshold is crossed. You do not decide what the organization is willing to lose. Risk appetite and tolerance are set by senior leadership, and risk acceptance requires a named risk owner with authority proportional to the size of the risk.

The manager-lens question: who has to sign this, and have I given them what they need to sign it?

Two named traps. Any answer option where the security manager unilaterally accepts a risk is almost always wrong, however sensible it sounds. And residual risk is not eliminated risk. Controls reduce risk; they never remove it, and what remains still needs an owner, monitoring, and a place on the register. The same goes for insurance: transferring the financial impact does not transfer the accountability.

Study time: roughly a fifth of your hours, matching the weight. The vocabulary rewards flashcards more than reading.

Domain 3: Information Security Program (33%)

Domain 3 is the largest single block on the exam, and it is really two subjects that are tested differently.

Program development is the build. It turns an approved strategy into an operating capability with a charter, and plans resources across people, process, technology, and budget. Identifying and classifying information assets sits here, as does choosing the frameworks the program runs on: ISO/IEC 27001 and 27002, the NIST Cybersecurity Framework, the NIST SP 800-series. So does the policy and standards hierarchy, and metrics designed to answer a leadership question rather than a technical one.

Program management is the run. Control design and selection by function (preventive, detective, corrective, deterrent, compensating) and by category (administrative, technical, physical), testing those controls for design effectiveness and for operating effectiveness, awareness and training including role-based training for the groups that create the most risk, third-party and fourth-party vendor management across the contract life cycle, and reporting program results to boards and executives.

Keeping the two halves separate pays off, because the questions tilt differently. Development questions ask what should exist and in what order. Management questions ask what to do now that it exists and something has gone sideways.

The manager-lens question: does this scenario need something built, or something run?

Two named traps. The first is the vanity metric. A number that counts activity (scans run, patches applied, tickets closed) without connecting to risk reduction or an objective is the wrong answer whenever a better-framed metric is on offer. The second is treating a signed contract or a vendor attestation report as the end of third-party risk. CISM expects ongoing monitoring of adherence, including your vendor's vendors and the concentration risk that comes from leaning on one dominant provider.

Study time: a third of your hours, and the biggest single block in your plan.

Domain 4: Incident Management (30%)

Domain 4 splits cleanly into readiness and execution, and knowing which side a question sits on is half the work.

Readiness is everything you do before anything happens. That means the incident response plan and how it interlocks with the business continuity plan and the disaster recovery plan, the response life cycle from preparation through lessons learned, and building a response team with clear authority. It also means the business impact analysis that produces recovery time objective, recovery point objective, and maximum tolerable downtime, plus the recovery strategies matched to those numbers. Incident classification sits here too, separating an event from an incident from a breach, as does the testing ladder: checklist review, walkthrough, tabletop, simulation, parallel test, full interruption test.

Execution is what happens once the alert fires: detection tooling and mean time to detect, investigation, containment, communications, eradication, recovery, and the post-incident review.

Two execution concepts are tested more than any others. The containment decision is a business judgment, not a technical one: you weigh the impact of the containment action against the impact of the incident continuing. Short-term containment stops the spread now (isolating a host from the network while leaving it powered on, so volatile memory survives for forensics), long-term containment holds the line while eradication is prepared, and the standing tension is speed against evidence. Chain of custody is the documented record of who controlled a piece of evidence at every point, when, and how its integrity was verified. Break it and genuine evidence can become inadmissible.

The manager-lens question: what does the plan say, and what will this action cost the business?

Two named traps. Restoring service before the root cause is eradicated is a classic wrong answer, because it reintroduces the threat. And recovery objectives come from the business through the business impact analysis, never from what IT happens to have available. If an option picks a recovery strategy based on existing capability rather than on the RTO and RPO, it is wrong.

Study time: a third of your hours. Drill the recovery vocabulary until RTO and RPO cannot be swapped under pressure.

Which CISM domains should you study most?

Follow the weights, with one deliberate exception. If you have 100 study hours, a defensible split is 30 hours on Domain 3, 30 on Domain 4, 20 on Domain 2, and 20 on Domain 1. That gives the majority of your time to the two domains carrying 63% of the questions, which is the right call and the one most candidates get wrong by studying in domain order until they run out of calendar.

The exception is Domain 1. On weight alone it deserves about 17 hours of that 100, and it is still the worst place to cut. Domain 1 teaches the governance instinct, and that instinct decides Domain 3 and Domain 4 questions constantly: who approves this, who owns it, does leadership need to hear about it, is this my call at all. Candidates who skim governance because it is only 17% then lose points in the heavyweight domains without understanding why. Study Domain 1 first, properly, then spend the bulk of your remaining time in Program and Incident Management.

Background matters too. From a hands-on security role, the technical content in Domains 3 and 4 will feel easy and you will still answer wrong, because you answer as a builder. From audit or compliance, the lens is already right and the vocabulary is the gap. Both are fixed by practice questions rather than rereading, which is the argument for a book with full-length practice exams: the ISACA CISM Study Guide teaches all four domains in plain English, with chapter space allocated to the same 17/20/33/30 weights the 2022 outline uses, which the 2026 update shifts by only a single point. For the overall challenge see how hard the CISM exam is, and CISA versus CISM compares the two credentials.

Are the CISM domains changing in November 2026?

Yes, and it matters more on this page than anywhere else, because the weight table is the thing that moves. ISACA has confirmed that the CISM reflects updated job practice areas from 3 November 2026, bringing in enterprise architecture and information security architecture content. Exams sat up to November 2 test the outline effective 2022, with the 17/20/33/30 weights above. From November 3 the published weights are:

Domain 2022 outline 2026 outline
1. Information Security Governance 17% 18%
2. Information Security Risk Management 20% 20%
3. Information Security Program 33% 33%
4. Incident Management 30% 29%

One point transfers from Incident Management to Governance, and no domain is added, removed, or renamed. On a 150-question paper that is roughly one and a half questions, so the study split above survives the changeover: Domains 3 and 4 still carry the bulk of the exam, at 62% instead of 63%.

The sub-areas and supporting tasks underneath the 2026 weights are not posted yet, so treat any third-party breakdown of the new subtopics as unconfirmed. The November 2026 CISM exam changes tracks what ISACA has actually announced.

FAQ

How many CISM domains are there?

Four: Information Security Governance, Information Security Risk Management, Information Security Program, and Incident Management. Their weights are 17%, 20%, 33%, and 30% under the outline effective 2022, which applies to exams sat up to November 2, 2026. From November 3, 2026 the published weights become 18%, 20%, 33%, and 29%. The four names and the four-domain structure are unchanged.

Which CISM domain has the most questions?

Domain 3, Information Security Program, at 33% of the exam. On a 150-question paper that is roughly 50 questions, about twice what Domain 1 is worth. Domain 4 is close behind at 30%, or around 45 questions.

Which CISM domain is hardest?

It depends on your background more than on the content. Technical candidates struggle most with Domains 1 and 2, where the correct answer is a governance or ownership decision rather than a fix. Audit and GRC candidates usually find Domain 4 harder, because incident execution carries the most operational detail. Both groups lose points for the same reason: answering from the wrong seat.

Do I need to pass each CISM domain separately?

No. CISM produces a single scaled score from 200 to 800, and 450 passes. There is no per-domain minimum, which is why weighting your study toward the 33% and 30% domains is the rational move.

Should I study the CISM domains in order?

Study Domain 1 first, then follow the weights. Domain 1 is short but it sets the answering instinct the other three depend on, so learning it last leaves you guessing on governance-flavored questions inside Domains 3 and 4. After that, give Program and Incident Management the majority of your remaining hours.


Looking for a plain-English CISM guide? ISACA CISM: Simply Certified Study Guide covers all four domains with three full-length practice exams, every answer explained.

Simply Certified is an independent publisher. CISM and ISACA are trademarks of ISACA. Our books are independent study material and are not affiliated with, endorsed by, or sponsored by ISACA.