CISM Domain 4: Information Security Incident Management (ISIM) [2022 update] (2024)

ISACA CISM

When it comes to proving technical competency and business skills in enterprise information security, IT professionals have no better option than becoming CISM certified. The route to attaining CISM involves a crucial exam, which tests a candidate on four knowledge areas (otherwise known as CISM domains).

Incident management (IM) identifies, evaluates, manages and documents security risks that may adversely affect an organization’s information assets. Expertise in IM proves that you can help an organization become more resilient to security incidents while reducing liability and legal exposure.

Let’s dive into the specifics of the IM domain and how it has changed after the latest CISM exam update.

CISM Domain 4: Information Security Incident Management (ISIM) [2022 update] (1)

$150,040 average salary

ISACA CISM is one of the industry's highest-paying cybersecurity certifications for 2023. Take your information security management career to new heights and enroll now to claim your Exam Pass Guarantee!

View Pricing

Incident management overview

Before the updated CISM exam that became effective on June 1, 2022, incident management had a 19% weightage with 29 exam questions. But after the exam refresh, its weightage increased to 30% with 45 exam questions. This points to the fact that ISACA (the exam creator) now emphasizes the incident management domain, which is crucial to mitigating security events and preventing disruptions in operations.

Candidates will have to demonstrate the ability to contain and manage disruptions, including environmental disruptions (e.g., earthquakes, storms), technical disruptions (e.g., DDoS and malware intrusions), and the broad category of mistakes and intentional acts (e.g., fraud and espionage). The primary cause of each disruption must be clearly defined, and the incident response must be consistent and easy to understand for relevant stakeholders (IT department, management, incident handlers and end users).

Organizations look for proficiency in incident management because such expertise can help them:

  • Diagnose incidents quickly and accurately
  • Identify root causes
  • Minimize and contain the damage
  • Document and report
  • Deploy improvements to prevent a recurrence
  • Restore affected systems and services

CISM candidates should also note that employers will expect them to balance incident management capabilities with baseline security, disaster recovery, and business continuity. For example, if the incident response will take a while to execute, it would be wise to raise the baseline security level. Additionally, candidates should know when the inability to effectively manage a security event calls for a disaster declaration.

What’s new in the incident management domain?

ISACA has divided the incident management domain into two sections:

  • Section 1: Incident management readiness
  • Section 2: Incident management operations

The updated exam also adds a few new topics to the IM domain:

  • Incident Response Concepts.Candidates must show a general understanding of the different concepts relevant to incident response. Examples include basic security principles (e.g., confidentiality and availability), network protocols (e.g., Address Resolution Protocol), and network applications and services (e.g., network file system and secure shell).
  • Incident Management and Incident Response Plans. A new addition to CISM domain 4, this module includes everything from IM resources and objectives to metrics, procedures, and the status of incident response capability.
  • Business Continuity Plan (BCP).This is a new section in domain 4 and includes important measurements like BIA (Business Impact Analysis), MTD (Maximum Tolerable Downtime), and RPO (Recovery Time Objective).
  • Incident Management Systems. A new, independent module in CISM domain 4, incident management systems, explores areas like endpoint detection and response and managed incident strategies.
  • Incident Containment Methods. Candidates may be asked to elaborate on the procedures and strategies for containing an incident (e.g., disabling certain functions, shutting down a system etc.)
  • Incident Eradication and Recovery. This covers both eradication activities and recovery as they relate to the operational areas of the business.

Incident management exam outline

The new CISM exam outline contains a few subtopics that previously weren’t present in the incident management knowledge domain. Here’s a brief overview of what you need to prepare for:

CISM Domain 4: Incident Management

Section 1: Incident Management ReadinessSection 2: Incident Management Operations1.1. Incident Response Plan2.1 Incident Management Techniques and Tools1.2 Business Impact Analysis2.2 Incident Investigation and Evaluation1.3 Business Continuity Plan2.3 Incident Containment Methods1.4 Disaster Recovery Plan2.4 Incident Response Communications (e.g., notification, reporting, escalation)1.5 Incident Categorization/ Classification2.5 Incident Recovery and Eradication1.6 Incident Management Testing, Evaluation, and Training2.6 Post-incident Review Practices

CISM Domain 4: Information Security Incident Management (ISIM) [2022 update] (2)

$150,040 average salary

ISACA CISM is one of the industry's highest-paying cybersecurity certifications for 2023. Take your information security management career to new heights and enroll now to claim your Exam Pass Guarantee!

View Pricing

Summary of incident management

CISM domain 4 covers all the strategies required to manage and respond to unexpected disruptive events. Candidates should be able to do this within an acceptable interruption window (AIM) to minimize the impact on clients and their trust in the organization. The domain may traverse through disaster recovery and business continuity procedures, so candidates should also be prepared for those.

If you’re scheduled to take the CISM exam, familiarizing yourself with the intricate details of incident management will help you ace 30% of the assessment. Hopefully, this domain overview will broaden your horizon and help you develop an effective incident management plan. Check the ISACA CISM hub for a detailed overview of all CISM domainsand other topics related to the CISM exam.

Sources

CISM Domain 4: Information Security Incident Management (ISIM) [2022 update] (2024)

FAQs

How many questions do I need to get right to pass CISM? ›

To get CISM certified, you need to: a) Pass the CISM Exam, a four-hour, 150-question test on four domains: Information Security governance, Information Risk Management, Information Security program development and management, and Information Security incident management. You need a score of 450 out of 800 to pass.

How hard is the ISACA CISM exam? ›

Yes, the CISM exam is said to be tough to pass. However, with plenty of focused studying, working through practice exams, and IS/IT management experience, most test-takers successfully pass and qualify for certification.

How to crack a CISM exam? ›

Read Answer Explanations: When practicing with any questions, carefully read the answer explanations. This will help you grasp why a particular answer is correct or incorrect, allowing for a deeper understanding of the material. Adopt a Managerial Perspective: Remember that the CISM exam focuses on management.

When was the CISM exam last updated? ›

On June 1, 2022, ISACA introduced a new CISM exam and consequently updated the exam outline. Changing the outline means the CISM job practice areas have changed. ISACA CISM is one of the industry's highest-paying cybersecurity certifications for 2023.

What is the failure rate for CISM? ›

Nonetheless, passing the exam is not a simple task. There is clear evidence that CISM difficulty is incredible, based on the fact that only 50-60% of first-time test-takers succeed. It is a challenging exam with many questions that will test your technical understanding.

Which test is harder CISSP or CISM? ›

Many find CISSP tougher due to its broad content, while CISM seems more doable with the right background. Both certifications, from ISACA and a certification consortium, boost chances for senior management roles by showing expertise in different security fields.

Is CISM harder than CISA? ›

However, most IT professionals will find CISM easier than CISA, provided they gel with the required governance and managerial mindset. CISM is considered more advanced only because it is targeted at information security managerial roles for professionals who have advanced further in their IT careers.

Can I take CISM exam without experience? ›

CISM certification requirements

You can still take the CISM exam even if you haven't met the experience requirements yet, although you'll have to meet those before getting certified.

How many hours to study for CISM? ›

If this is your first information security exam, give yourself at least ten hours to review and practice each of the four CISM domains. That's 40 to 50 hours of focused study time.

What is the pass rate for CISM first time? ›

Passing the CISM exam is tough, with a first-time pass rate of 50-60 percent. The exam lasts four hours and consists of 150 multiple-choice questions.

Does CISM expire after 3 years? ›

The CISM Certification journey does not end even after obtaining the certificate. It expires after three years from the date of issue. Candidates must pay the renewal fee and earn CPE credits as per ISACA CPE policy requirements to maintain their certification.

How many CISM holders are there? ›

There are more than 48,000 CISM-certified professionals worldwide, according to ISACA, the global association that offers the credential [1].

How much to pass CISM? ›

The CISM exam can be taken either online or in person, consists of 150 multiple-choice questions, and is scored on a scale of 200 to 800, with 450 being a passing score. (If you don't pass, you can retake the exam as often as four times a year, with a brief waiting period between attempts.)

How many questions do I need to get right on CISA? ›

Its structure involves 150 multiple-choice questions, spanning areas such as IT Governance and Information Systems Auditing. Each question gives you four options, but only one's correct! Remember, not all questions have the same value. You're aiming for at least 450 out of 800 to pass.

What is the passing score for the CISSP exam? ›

The exam is of six hours' duration and consists of 250 questions from eight goliath domains; the minimum requirement is 70%, and the CISSP passing score is 700 out of 1000.

What is harder CISA or CISM? ›

CISA is generally considered more challenging than CISM due to its focus on technical skills and audit processes. For example, CISA requires a deeper understanding of information systems auditing, control, and security compared to CISM's emphasis on information security management.

Top Articles
Latest Posts
Article information

Author: Reed Wilderman

Last Updated:

Views: 6503

Rating: 4.1 / 5 (52 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Reed Wilderman

Birthday: 1992-06-14

Address: 998 Estell Village, Lake Oscarberg, SD 48713-6877

Phone: +21813267449721

Job: Technology Engineer

Hobby: Swimming, Do it yourself, Beekeeping, Lapidary, Cosplaying, Hiking, Graffiti

Introduction: My name is Reed Wilderman, I am a faithful, bright, lucky, adventurous, lively, rich, vast person who loves writing and wants to share my knowledge and understanding with you.