CISM Study Guide 2026

Everything you need to pass the CISM exam in one place: the exam format, every topic to study, real practice questions with explanations, flashcards, and full-length practice tests. Free, no sign-up needed.

๐Ÿ“‹ CISM Exam Format at a Glance

150
Questions
240 min
Time Limit
70.00%
Passing Score

๐Ÿ“š CISM Topics to Study (33)

โœ๏ธ Sample CISM Questions & Answers

1. A CISM is conducting a risk assessment and discovers a high likelihood threat with low potential impact. This risk should be:
โœ“ Evaluated in the context of the organization's risk appetite

All risks, regardless of their individual dimensions, must be evaluated against the organization's defined risk appetite before determining the appropriate response.

2. Which of the following represents a governance control rather than a technical control?
โœ“ Acceptable use policy

An acceptable use policy is a governance (administrative) control that defines rules and expectations for users, rather than a technical enforcement mechanism.

3. Which BC/DR test type carries the GREATEST risk of causing unplanned downtime?
โœ“ Full interruption test

A full interruption test shuts down primary systems and fully activates recovery procedures, carrying the highest risk of real outages if the recovery environment fails.

4. An organization's risk appetite statement should be approved by:
โœ“ The board of directors or executive leadership

Risk appetite is a strategic business decision that must be set and approved at the board or executive level to align with organizational objectives.

5. How often should a Business Continuity Plan be tested at MINIMUM according to best practices?
โœ“ At least annually, and after any significant change to the environment

Best practices and most frameworks require BCP testing at least annually and after any significant changes to ensure the plan remains effective and current.

6. An organization's board of directors is MOST responsible for which security governance activity?
โœ“ Setting risk appetite and oversight

The board of directors is responsible for setting the organization's risk appetite and providing oversight of the overall security posture.

๐ŸŽฏ Free CISM Practice Tests

๐Ÿ“– CISM Guides & Articles

Your CISM Study Path
1. Learn with Flashcards โ†’ 2. Drill Practice Tests โ†’ 3. Take the Full Exam Simulation
Was this helpful?
CISM Study Guide 2026 โ€” Exam Format, Topics & Practice Questions