May 13, 2025 By Kim Walsh Cybersecurity Certifications, Governance and Compliance

Every year or two someone publishes an article suggesting that the CISM is being displaced by newer credentials or that the security management certification landscape has moved past it. Every year or two I check the job postings and the salary surveys and reach the same conclusion: the CISM is doing just fine.

The Certified Information Security Manager from ISACA has been a significant credential in the security management space since it launched in 2002. That longevity is not an accident. It reflects a credential that was designed around the actual job that security managers do, has been maintained rigorously to stay current with the evolving threat and regulatory landscape, and is backed by an organization with deep credibility in the governance and audit space that gives the credential cross-functional recognition beyond the purely technical security world.

Let me tell you what is worth knowing about the CISM in 2025 specifically, because the current version of the exam reflects some meaningful content updates that are worth understanding before you plan your preparation.

The Information Security Governance domain has been updated to more directly address the intersection of security governance with AI risk, cloud governance, and third-party ecosystem management. These are not cosmetic additions. The practical reality of security governance in 2025 involves managing risk across a much more complex environment than the CISM content of even five years ago reflected. AI systems introduce governance questions that most organizations have not fully addressed. Third-party risk has become a primary attack surface category after several high-profile supply chain incidents. Cloud environments require governance approaches that are meaningfully different from on-premises governance. The updated content addresses these realities.

The Information Risk Management domain retains its foundational importance and has been refined to better address quantitative risk approaches that have been gaining traction in security programs. The ability to communicate risk in financial terms rather than purely technical or categorical terms is increasingly expected of security managers who need to justify investment to business leadership. The CISM content in this domain supports that capability more directly than previous versions did.

The Security Program Development and Management domain is where the credential most directly reflects the senior practitioner level it is designed for. Building and running a security program requires a different set of skills from doing security work. Understanding how to establish a security program that is appropriately sized and scoped for the organization, how to develop and maintain security policies and standards, how to manage security resources, and how to communicate program effectiveness to leadership are skills that distinguish security managers from security technologists. This is the domain that most clearly explains why the CISM has five-year experience requirements.

Incident Management has evolved to address the current incident landscape more directly, including ransomware response, cloud incident handling, and the coordination requirements of incidents that span multiple third-party environments. Tabletop exercise facilitation and the organizational communication aspects of incident response get appropriate coverage alongside the technical coordination content.

For people who are in security management roles or who are working toward them, the CISM remains the credential that most directly maps to the senior practitioner experience level and is most broadly recognized in hiring conversations for security leadership roles. The CISSP from ISC2 is the main credential in its competitive set and the comparison between them is worth understanding. The CISSP is broader in technical scope and tends to be more valued for roles that require cross-domain technical depth. The CISM is more focused on management and governance and tends to be more valued for roles that require leading a security function. Depending on where you are headed, one may be a stronger fit than the other.

The ISC2 CISSP details are at isc2.org if you want to compare the two credentials directly. The CISM information is at ISACA’s CISM page. Both require substantial professional experience and both are serious investments that pay off over the course of a security leadership career.

The short version: the CISM is worth pursuing if security management is where you are headed. It has not been displaced. It has kept pace. The organizations that matter in security hiring still recognize it and value it.

Kim Walsh

Kim Walsh is a CISSP and seasoned cybersecurity practitioner with deep, hands-on experience in enterprise security architecture, risk management, and compliance. She is passionate about bringing the next generation into the IT and AI space, actively mentoring young people who are just finding their footing in the field. As the mother of five kids, she has both the patience and the battle-tested communication skills to explain just about anything to just about anyone.