Certification Summary: For individuals who provide information security management and consulting. It is business-oriented and focuses on information risk management while addressing management, design and technical security issues at a conceptual level.
Initial requirements: Must pass the CISM exam which is offered annually twice a year at over 160 locations. You must also agree to adhere to the ISACA code of professional ethics. In addition, you must provide evidence of at least five years of experience working in the information security field, with at least 3 years of that in qualifying areas. The experience requirement can be partially met through qualifying substitutions for example: CISSP, CISA, a post graduate degree, or one of several other certifications).
Continuing requirements:
Once certified a CISM must comply with the Continuing Education requirements, annually. Those requirements are: a minimum of 20 continuing professional education (CPE) hours earned that year, pay the continuing education maintenance fee, comply with the ISACA Code of Professional Ethics, and in the third year of the fixed three-year certification cycle, you must also have completed a minimum of 120 CPE hours earned within that fixed three-year certification cycle.