CISM — Certified Information Security Manager
ISACA's information security management certification and one of the most recognized credentials for security managers and CISOs globally. Requires five years of IS management experience. DoD 8140 approved. CISM is explicitly management-focused — it validates governance, risk management, and program oversight rather than technical security skill, which is why it pairs well with technical certs like GCIH or GCFA rather than replacing them. Highly valued in financial services, audit-heavy industries, and senior management pipelines. Often listed alongside CISSP in CISO job requirements as the ISACA alternative for those who prefer the management orientation.
| Issuer | ISACA |
| Level | expert |
| Domains | Governance, Risk & Compliance, Oversight & Leadership, Security Architecture & Engineering |
| Practical weight | 0% |
| Cost (USD) | 760 |
| Renewal | 3 years |
| DoD 8140 | Yes |
| Skills | information_security_governance, information_risk_management, security_program_development, incident_management_governance |
Official certification page
Browse all 426 cybersecurity certifications on EBCertMap