Certification / Standards Authority

CISM: What It Verifies

Published
2026-08-01
Content type
Certification / Standards Authority
Read time
1 min

CISM — Certified Information Security Manager — is ISACA's credential for people who run a security program, not build one line by line. It covers four domains: information security governance, risk management, program development and management, and incident management.

What it verifies

CISM confirms someone has managed a security function, not just worked inside one. ISACA requires 5 years of security experience, including at least 3 years in security management across at least 3 of the 4 domains, before the credential is granted.

Who typically holds it

On the calibre° roster, CISM appears on CISO (Fractional) — the executive-level engagement where security strategy and board-level risk reporting are the deliverable, not a specific engineering task.

How calibre° verifies it

CISM status is checked against ISACA's credential registry before roster eligibility, the same primary-source standard applied to every certification calibre° lists — not a resume claim taken at face value. Full procedure: Verification.

02

FAQ

How is CISM different from CISSP?

CISM is management-only — governance, risk, and program leadership. CISSP spans both management and technical architecture across 8 domains. calibre° lists both separately by role because they verify different things.

Does CISM require renewal?

Yes — ISACA requires continuing education credits and an annual maintenance fee, which is why calibre° checks current status rather than a point-in-time claim.

Is CISM required for every fractional CISO engagement?

It's one of three certifications checked for that role — see [CISO (Fractional)](/calibre/roles#ciso-fractional) for the full set.

Specify the role. We calibrate the match.