CISM

What should you ask in a CISM interview, and how should candidates answer?

A CISM says someone can manage information security, not just operate it. These questions test the four exam domains in practice, with what a strong answer covers. Candidates get the questions to prepare for and three to ask back.

What should an employer ask a CISM candidate?

Each question maps to an exam domain, so you test what the role needs. Score each answer 1 to 4 on the free scorecard below.

  1. How would you align our security strategy with the business strategy?

    Listen for: Start from business objectives and risk appetite, turn them into security objectives, assign governance roles, and report in terms the board uses.

    Domain 1: Information Security Governance

  2. Who should own the information security policy, and who approves it?

    Listen for: Senior management owns it, the security function drafts and maintains it, an executive body approves it, and it is reviewed on a set cycle.

    Domain 1: Information Security Governance

  3. How would you run our first information risk assessment?

    Listen for: Assets with named owners, threats and vulnerabilities, likelihood and impact, a risk register, and treatment within the risk appetite.

    Domain 2: Information Security Risk Management

  4. A business unit wants to accept a high risk. What do you do?

    Listen for: Make sure an owner with the authority accepts it in writing, for a set period, within appetite, or escalate it.

    Domain 2: Information Security Risk Management

  5. How would you build a security program from scratch?

    Listen for: A gap assessment against a framework, a roadmap with budget and people, early wins, and measures from day one.

    Domain 3: Information Security Program

  6. How do you show the program is working?

    Listen for: Measures tied to objectives, trends over time, and reports that lead to decisions, not raw counts.

    Domain 3: Information Security Program

  7. Walk me through the first hour of an incident.

    Listen for: Triage and classify, activate the plan and roles, escalate, communicate, preserve evidence, and check legal and regulatory notice duties.

    Domain 4: Incident Management

  8. How do you know we are ready for an incident?

    Listen for: Tabletop and technical exercises on a schedule, and lessons learned that change the plan.

    Domain 4: Incident Management

CISM interview scorecard

CISM interview scorecard

Candidate: ______ Interviewer: ______ Date: ______

#QuestionListen forScore 1 to 4
1How would you align our security strategy with the business strategy?Start from business objectives and risk appetite, turn them into security objectives, assign governance roles, and report in terms the board uses.
2Who should own the information security policy, and who approves it?Senior management owns it, the security function drafts and maintains it, an executive body approves it, and it is reviewed on a set cycle.
3How would you run our first information risk assessment?Assets with named owners, threats and vulnerabilities, likelihood and impact, a risk register, and treatment within the risk appetite.
4A business unit wants to accept a high risk. What do you do?Make sure an owner with the authority accepts it in writing, for a set period, within appetite, or escalate it.
5How would you build a security program from scratch?A gap assessment against a framework, a roadmap with budget and people, early wins, and measures from day one.
6How do you show the program is working?Measures tied to objectives, trends over time, and reports that lead to decisions, not raw counts.
7Walk me through the first hour of an incident.Triage and classify, activate the plan and roles, escalate, communicate, preserve evidence, and check legal and regulatory notice duties.
8How do you know we are ready for an incident?Tabletop and technical exercises on a schedule, and lessons learned that change the plan.

Source: https://credentialpress.com/guides/cism-interview-questions

Which questions should a CISM candidate prepare for?

  1. Why CISM rather than CISSP?

    How to answer: CISM is about managing security as a business function. Say which management work you do.

  2. Tell me about a time you won budget for security.

    How to answer: The risk in business terms, the ask, the decision, and what it delivered.

  3. How do you report security to the board?

    How to answer: A few measures tied to risk appetite, trends, and the decisions you need from them.

  4. Have you checked the outline that applies to your exam date?

    How to answer: ISACA's CISM outline changes on 3 November 2026: governance rises to 18% and incident management falls to 29%. Show you planned for it.

What should a candidate ask the employer?

  • Who does the security leader report to?
  • How is the security budget set each year?
  • When was the incident response plan last tested?

Where next?

Also free: the CISM mind map, plus every other credential on our study tools page. For the full syllabus, the CISM Exam Guide and the CISM Practice Questions go domain by domain.

Frequently asked questions

What should an employer ask a CISM candidate?

Questions that test each exam domain in practice, for example: How would you align our security strategy with the business strategy? Who should own the information security policy, and who approves it? How would you run our first information risk assessment?

What should a CISM candidate ask the employer?

Who does the security leader report to? How is the security budget set each year? When was the incident response plan last tested?

How should a candidate prepare for a CISM interview?

CISM is about managing security as a business function. Say which management work you do.

Which books go deeper on CISM?

Cover of CISM Exam Guide

CISM Exam Guide

Certified Information Security Manager. 12 chapters, 342 pages.

Cover of CISM Practice Questions

CISM Practice Questions

Practice questions with full rationales, sized to the published domain weights. 213 pages.