CISM
Reddit take
AI summary of the Reddit excerpts below — not a quote
The CISM (Certified Information Security Manager) is widely regarded as a management-focused certification that shares significant content overlap with the CISSP. Within the professional community, it is frequently viewed as a logical next step or a more accessible alternative for those moving into leadership roles. While many practitioners find the exam easier than the CISSP due to its straightforward 150-question format, it still requires dedicated study to master the specific ISACA perspective on business-aligned security management.
Pros
- High degree of content overlap with the CISSP, making it easier for those who have already studied for or passed the latter.
- Strongly recognized industry standard for management and leadership tracks.
- Straightforward exam format consisting of a standard 150-question set.
- Valued for satisfying IAM Level 3 requirements for government and industry roles.
Cons
- Does not satisfy IAT Level 3 requirements, only IAM Level 3.
- Requires maintaining a relationship with a separate certification body (ISACA) if the user already holds ISC2 certifications.
- Some users find the ISACA-specific terminology and 'way of thinking' challenging despite technical knowledge.
Caveats
- While often called 'easier' than CISSP, some users still find it difficult and recommend specific study of the ISACA Question and Answer (QAE) database.
- Experience requirements for certification can vary; for example, a Master's degree may count for more years of experience (YOE) for CISM than for CISSP.
Best for
- Information security professionals moving into management or leadership roles.
- Individuals who have already passed the CISSP and want to leverage that knowledge for an additional credential.
- Those needing to meet IAM Level 3 compliance.
Avoid if
- You specifically require an IAT Level 3 certification.
- You want to avoid the administrative overhead and fees of maintaining multiple certification vendors.
This summary uses balanced time weighting with about a 122-month half-life. The evidence is drawn from 25 mentions within r/cissp between January 2025 and December 2025, with a median source age of approximately 405 days.
Sentiment
18 positive (72%) · 5 mixed (20%) · 2 negative (8%)
Trust + time weighted score: +62% · raw score 64%
What redditors said (10 of 25)
CISM was a few evenings with a glass of wine scanning the book.
I am looking at giving my CISM a go since there is a lot of information overlap between it and the CISSP.
CISM is easier to pass than CISSP
Do you just want to pass exams, then you will likely have more success with CISM.
Consider the CISM, CompTIA Security+ or even the sscp as your launching point.
Can't say the CISM helped me on CISSP but the others did.
Correct. I'm thinking of taking CISM before the 4th attempt
I would do CISSP first to satisfy both the IAT-IAM level 3 requirement. CISM only satisfies IAM Level 3.
CISSP is the harder one and will make CISM fairly easy if you do well on CISSP.
This means I would qualify to get the CISM certification, but I would be an associate of ISC2 (CISSP) for one more year since my Masters counts as 2YOE for CISM and only 1YOE for CISSP.
Compare
CISM vs CompTIA Security+CISM vs AB-900CISM vs CompTIA Network+
Related
- CISSP Official Study Guide · related · 402 mentions
- Destination CISSP · related · 254 mentions
- Official Study Guide (OSG) 10th Edition · related · 11 mentions
- CISSP Common Body of Knowledge · related · 10 mentions