Travis Duncan Logo Image
Travis Duncan

CISM Review

My experience with the CISM exam and the ISACA Online QAE (Questions, Answers, and Explanations) Database.

CISM QAE Review
CISM and QAE Review

Project Overview

I agree with the sentiment I've heard and read: I felt CISM was easier than CISSP. However, it is of the utmost importance to approach the business/security problems in each question using ISACA's methods/mindset.

This is not a technical exam by any means.

I agree with the sentiment I've heard and read: I felt CISM was easier than CISSP. However, it is of the utmost importance to approach the business/security problems in each question using ISACA's methods/mindset.

I think the biggest tip I can give is to focus on UNDERSTANDING business processes and entities rather than memorizing minutia of technical details or framework documentation. Certainly, some level of knowledge/memorization is needed. However, a hefty amount of your success will come from understanding how ISACA is asking/training you to think about information security.

Build your understanding of how ISACA would like you to answer questions about business and security. Understand the different entities and people involved in business processes covered in the exam material. Understand the preferred roles and decisions throughout the phases of processes and how those choices may change under varying circumstances. This sounds very complicated but practicing in the QAE Database helped me to understand it enough to pass.

Resources Used to Prepare

CISM QAE Database
Pocket Prep mobile app
WannaPractice mobile app (2-month CISM subscription)
Nemstar Cyber Training CISM YouTube videos
Prabh Nair CISM YouTube videos
Kevin Henry's PluralSight course
Hemang Doshi Udemy course
"Think Like a Manager" video from Gwen Bettwy's Tactical Security Inc. YouTube channel
CISM All-in-One book