Home › Exams › IT Certifications › CISM › Information Security Governance

CISM · 17%

Information Security Governance

Information Security Governance is 17% of the ISACA CISM (CISM), administered by ISACA. It falls under the IT Certifications category.

Practice CISM on iPhone → Mac → Back to CISM Overview

Domain Details

Detail Information
Domain Information Security Governance
Exam ISACA CISM (CISM)
Domain Weight 17%
Governing Body ISACA
Available in App PMP CAPM ITIL 4 Exam Prep 2026
Official Source ISACA official website ↗

Try a Practice Question

Sample CISM Practice Question

This original C3RT practice item is from the CISM question bank. It is not an official or released exam question.

A financial institution has established a risk appetite that allows for a moderate level of risk. During a risk assessment, they discover a critical vulnerability in their transaction processing system. What should be their immediate response?

  1. Accept the risk due to existing controls
  2. Implement immediate remediation actionsCorrect
  3. Communicate the risk to stakeholders
  4. Reassess the risk appetite

Rationale

The immediate response should be to implement remediation actions, as the identified critical vulnerability could pose significant risk, exceeding their risk appetite. Option A misinterprets risk acceptance, while Option C, although important, is not the immediate action, and Option D is unnecessary at this stage.

CISM Information Security Governance: FAQ

How much of the CISM covers Information Security Governance?

Information Security Governance accounts for 17% of the CISM, which has 150 questions total. ISACA publishes the official exam content outline with the most current weighting. The C3RT app covers all 4 CISM content areas.

What is the CISM exam format and how does Information Security Governance fit in?

The CISM has 4 content areas across 150 questions in 4 hours, with a passing score of 450/800. Information Security Governance is content area 1 of 4 and carries 17% of the total exam weight. The other content areas are Information Security Risk Management, Information Security Program, Incident Management.

How do I study for the Information Security Governance section of the CISM?

Targeted practice by content area is the most effective approach. The C3RT PMP CAPM ITIL 4 Exam Prep 2026 app for iOS and Mac tags every practice question by content area, so you can isolate Information Security Governance questions, track your accuracy, and focus study time on your weak spots. Combine focused practice sets with full-length timed mock exams as your test date approaches.

How many questions are on the CISM and what is the passing score?

The CISM consists of 150 questions in 4 hours, with a passing score of 450/800. It is administered by ISACA and the exam fee is $575 (ISACA members) / $760 (non-members). The C3RT app includes full-length practice exams that mirror the real format across all 4 content areas.

Where can I find official ISACA resources for Information Security Governance?

The official source for CISM content outlines and study resources is the ISACA website. The exam blueprint, which details all content areas including Information Security Governance, is published there. C3RT is not affiliated with ISACA. It is a third-party practice platform that supplements official materials with 150+ practice questions, flashcards, and study tools across all 4 content areas.

Information Security Governance is a content area on the ISACA CISM (CISM), a IT Certifications exam administered by ISACA. C3RT is not affiliated with ISACA. Certification names and trademarks are the property of their respective organisations. Official exam information is available at the ISACA website.