Disclaimer: Please be advised that the CISM Exam Content Outline will be updated effective 3 November 2026. Starting on that date the CISM Exam will reflect the new Exam Content Outline. Updated preparation material for the new Exam Content Outline will be available for purchase in September 2026. Purchase of current material will not grant you access to the newer material at a later date. Learn more.
This is an electronic book designed to be accessible anytime through your browser without the need for downloads or printing. Please review the FAQs to ensure you understand the requirements prior to purchase, as all sales are final.
The CISM Review Manual 16th Edition is a comprehensive reference guide designed to help individuals prepare for the CISM exam and understand information security management roles and responsibilities. The 16th edition manual is organized to assist candidates in understanding essential concepts and studying the following domain areas:
- Information Security Governance: including ENTERPRISE GOVERNANCE - organizational culture, legal, regulatory and contractual requirements, organizational structures, roles and responsibilities. INFORMATION SECURITY STRATEGY - information security strategy development, information governance frameworks and standards, strategic planning (e.g., budgets, resources, business case
- Information Security Risk Management: including INFORMATION SECURITY RISK ASSESSMENT - emerging risk and threat landscape, vulnerability and control deficiency analysis, risk assessment and analysis. INFORMATION SECURITY RISK RESPONSE - risk treatment/risk response options, risk and control ownership, risk monitoring and reporting
- Information Security Program: including INFORMATION SECURITY PROGRAM DEVELOPMENT - information security program resources, information asset identification and classification, industry standards and frameworks for information security, information security policies, procedures and guidelines, information security program metrics. INFORMATION SECURITY PROGRAM MANAGEMENT - information security control design and selection, information security control implementation and integrations, information security control testing and evaluation, information security awareness and training, management of external services, information security program communications and reporting
- Incident Management: including INCIDENT MANAGEMENT READINESS - incident response plan, business impact analysis, business continuity plan, disaster recovery plan, incident classification/categorization, incident management training, testing and evaluation. INCIDENT MANAGEMENT OPERATIONS - incident management tools and techniques, incident investigation and evaluation, incident containment methods, incident response communications, incident eradication and recovery, post-incident review practices
The CISM Review Manual 16th Edition offers an easy-to-navigate format. Each of the book’s chapters has been divided into two sections for focused study. Section one of each chapter contains:
- Definitions and objectives for the four areas
- Task and knowledge statements
- Self-assessment questions, answers, and explanations
- Suggested resources for further study
Section two of each chapter consists of reference material and content that support the knowledge statements. The material enhances CISM candidates’ knowledge and/or understanding when preparing for the CISM certification exam. Also included are definitions of terms most found on the exam.
While this manual is an excellent stand-alone document for individual study and can be used as a guide or reference for study groups and chapters conducting local review courses. It can also be used in conjunction with the:
- CISM Questions, Answers & Explanations Manual 10th Edition