CISM: What It Verifies
- Published
- 2026-08-01
- Content type
- Certification / Standards Authority
- Read time
- 1 min
CISM — Certified Information Security Manager — is ISACA's credential for people who run a security program, not build one line by line. It covers four domains: information security governance, risk management, program development and management, and incident management.
What it verifies
CISM confirms someone has managed a security function, not just worked inside one. ISACA requires 5 years of security experience, including at least 3 years in security management across at least 3 of the 4 domains, before the credential is granted.
Who typically holds it
On the calibre° roster, CISM appears on CISO (Fractional) — the executive-level engagement where security strategy and board-level risk reporting are the deliverable, not a specific engineering task.
How calibre° verifies it
CISM status is checked against ISACA's credential registry before roster eligibility, the same primary-source standard applied to every certification calibre° lists — not a resume claim taken at face value. Full procedure: Verification.
FAQ
How is CISM different from CISSP?
CISM is management-only — governance, risk, and program leadership. CISSP spans both management and technical architecture across 8 domains. calibre° lists both separately by role because they verify different things.
Does CISM require renewal?
Yes — ISACA requires continuing education credits and an annual maintenance fee, which is why calibre° checks current status rather than a point-in-time claim.
Is CISM required for every fractional CISO engagement?
It's one of three certifications checked for that role — see [CISO (Fractional)](/calibre/roles#ciso-fractional) for the full set.
Specify the role. We calibrate the match.