Scroll to top
CISM

The 4 CISM Domains Explained

What the four domains cover.

ISACA
Training delivered by Virtual Infrastructure Services LLC — an accredited ISACA Training Organization.

The CISM exam is organized into four domains that trace the arc of a security-management role — from setting governance to running incident response. Here's what each covers.

Domain 1 — Information Security Governance

Setting direction: enterprise governance, organizational culture, structures, roles and responsibilities, legal, regulatory and contractual requirements, information security strategy, governance frameworks and standards, and strategic planning.

Domain 2 — Information Security Risk Management

Managing risk: the risk and threat landscape, vulnerability and control-deficiency analysis, risk assessment, evaluation and analysis, information risk response, and risk monitoring, reporting and communication.

Domain 3 — Information Security Program

Building the program: program development and resources, standards and frameworks, defining a program road map, program metrics and management, awareness and training, integrating security with IT operations, and program communications, reporting and performance management.

Domain 4 — Incident Management

Responding when it matters: incident management and response overview, response plans, classification and categorization, operations, tools and technologies, investigation, evaluation, containment and communication, eradication, recovery and review — plus business impact, continuity, disaster recovery and testing.

Ready to go deeper? See the CISM exam guide for format and study plan, or explore CISM exam-prep training.

Get certified

Start foundational prep today and join our next monthly live-virtual cohort.

Next cohort: August 31, 2026 (monthly)

Live virtual, instructor-led

Pricing: from $1,195

RegisterRequest a Quote
CISM — Certified Information Security Manager