experience_req
5 yrs security work, 3 in security management (up to 2-yr waiver)
exam_format
150 multiple-choice questions
exam_length
4 hours
exam_fee
$575 members / $760 non-members
renewal
Every 3 yrs · 120 CPEs (20/yr min) + $45–$85/yr fee
Issuers change fees and exam details, so confirm current requirements with ISACA.
Who it's for
Security professionals who manage, design or oversee an enterprise security program. It is aimed at managers and aspiring CISOs more than hands-on technical staff.
Information Security ManagerCISORisk ManagerGRC Lead
The four exam domains
- 01Information Security Governance
- 02Information Security Risk Management
- 03Information Security Program
- 04Incident Management
Where it sits in the cert path
- Security+Entry
- CySA+Intermediate
- CISMAdvanced