CISM
What should you ask in a CISM interview, and how should candidates answer?
A CISM says someone can manage information security, not just operate it. These questions test the four exam domains in practice, with what a strong answer covers. Candidates get the questions to prepare for and three to ask back.
What should an employer ask a CISM candidate?
Each question maps to an exam domain, so you test what the role needs. Score each answer 1 to 4 on the free scorecard below.
How would you align our security strategy with the business strategy?
Listen for: Start from business objectives and risk appetite, turn them into security objectives, assign governance roles, and report in terms the board uses.
Domain 1: Information Security Governance
Who should own the information security policy, and who approves it?
Listen for: Senior management owns it, the security function drafts and maintains it, an executive body approves it, and it is reviewed on a set cycle.
Domain 1: Information Security Governance
How would you run our first information risk assessment?
Listen for: Assets with named owners, threats and vulnerabilities, likelihood and impact, a risk register, and treatment within the risk appetite.
Domain 2: Information Security Risk Management
A business unit wants to accept a high risk. What do you do?
Listen for: Make sure an owner with the authority accepts it in writing, for a set period, within appetite, or escalate it.
Domain 2: Information Security Risk Management
How would you build a security program from scratch?
Listen for: A gap assessment against a framework, a roadmap with budget and people, early wins, and measures from day one.
Domain 3: Information Security Program
How do you show the program is working?
Listen for: Measures tied to objectives, trends over time, and reports that lead to decisions, not raw counts.
Domain 3: Information Security Program
Walk me through the first hour of an incident.
Listen for: Triage and classify, activate the plan and roles, escalate, communicate, preserve evidence, and check legal and regulatory notice duties.
Domain 4: Incident Management
How do you know we are ready for an incident?
Listen for: Tabletop and technical exercises on a schedule, and lessons learned that change the plan.
Domain 4: Incident Management
CISM interview scorecard
CISM interview scorecard
Candidate: ______ Interviewer: ______ Date: ______
| # | Question | Listen for | Score 1 to 4 |
|---|---|---|---|
| 1 | How would you align our security strategy with the business strategy? | Start from business objectives and risk appetite, turn them into security objectives, assign governance roles, and report in terms the board uses. | |
| 2 | Who should own the information security policy, and who approves it? | Senior management owns it, the security function drafts and maintains it, an executive body approves it, and it is reviewed on a set cycle. | |
| 3 | How would you run our first information risk assessment? | Assets with named owners, threats and vulnerabilities, likelihood and impact, a risk register, and treatment within the risk appetite. | |
| 4 | A business unit wants to accept a high risk. What do you do? | Make sure an owner with the authority accepts it in writing, for a set period, within appetite, or escalate it. | |
| 5 | How would you build a security program from scratch? | A gap assessment against a framework, a roadmap with budget and people, early wins, and measures from day one. | |
| 6 | How do you show the program is working? | Measures tied to objectives, trends over time, and reports that lead to decisions, not raw counts. | |
| 7 | Walk me through the first hour of an incident. | Triage and classify, activate the plan and roles, escalate, communicate, preserve evidence, and check legal and regulatory notice duties. | |
| 8 | How do you know we are ready for an incident? | Tabletop and technical exercises on a schedule, and lessons learned that change the plan. |
Source: https://credentialpress.com/guides/cism-interview-questions
Which questions should a CISM candidate prepare for?
Why CISM rather than CISSP?
How to answer: CISM is about managing security as a business function. Say which management work you do.
Tell me about a time you won budget for security.
How to answer: The risk in business terms, the ask, the decision, and what it delivered.
How do you report security to the board?
How to answer: A few measures tied to risk appetite, trends, and the decisions you need from them.
Have you checked the outline that applies to your exam date?
How to answer: ISACA's CISM outline changes on 3 November 2026: governance rises to 18% and incident management falls to 29%. Show you planned for it.
What should a candidate ask the employer?
- Who does the security leader report to?
- How is the security budget set each year?
- When was the incident response plan last tested?
Where next?
Also free: the CISM mind map, plus every other credential on our study tools page. For the full syllabus, the CISM Exam Guide and the CISM Practice Questions go domain by domain.
Frequently asked questions
What should an employer ask a CISM candidate?
Questions that test each exam domain in practice, for example: How would you align our security strategy with the business strategy? Who should own the information security policy, and who approves it? How would you run our first information risk assessment?
What should a CISM candidate ask the employer?
Who does the security leader report to? How is the security budget set each year? When was the incident response plan last tested?
How should a candidate prepare for a CISM interview?
CISM is about managing security as a business function. Say which management work you do.
Which books go deeper on CISM?

Certified Information Security Manager. 12 chapters, 342 pages.

Practice questions with full rationales, sized to the published domain weights. 213 pages.
Sources
Credential Press is independent of ISACA.