Every answer in the ISACA Certified Information Security Manager (CISM日本語版) set from ValidExam is expert-verified — 1193 practice questions for the CISM日本語 exam you can trust in 2026.
ISACA CISM日本語 Exam Overview:
| Certification Vendor: | ISACA |
|---|---|
| Exam Name: | Certified Information Security Manager |
| Exam Number: | CISM |
| Passing Score: | 450 (out of 800) |
| Related Certifications: | CISM |
| Real Exam Qty: | 150 |
| Exam Price: | $575 (Member) / $760 (Non-Member) |
| Exam Duration: | 240 minutes |
| Exam Format: | Multiple Choice |
| Available Languages: | Chinese-Simplified, Spanish, German, Japanese, English, French |
| Certificate Validity Period: | 3 years (requires maintenance fees and CPE) |
| Sample Questions: | ![]() |
| Exam Way: | Computer-based testing at authorized PSI testing centers or remotely proctored. |
| Pre Condition: | To earn the CISM certification, candidates must pass the exam and possess a minimum of five years of information security work experience with a minimum of three years of information security management work experience in three or more of the CISM domains. Substitutions and waivers for general information security experience are available. |
| Official Syllabus URL: | https://www.isaca.org/credentialing/cism |
ISACA CISM日本語 Exam Syllabus Topics:
| Section | Weight | Objectives |
|---|---|---|
| Information Security Risk Management | 20% | - Establish and/or maintain a process for information asset identification, classification, risk assessment and ownership - Evaluate information security controls to determine whether they are appropriate and effectively mitigate risk - Integrate risk management into business and IT processes - Determine appropriate risk treatment options - Monitor and communicate the information security risk posture - Ensure that risk assessments, vulnerability assessments and threat assessments are performed consistently, at appropriate times, and to identify acceptable risk - Identify legal, regulatory, organizational and other applicable compliance requirements - Identify and/or recommend risk treatment options |
| Information Security Governance | 17% | - Establish, monitor, evaluate and report information security management metrics - Develop business cases to support investments in information security - Establish and/or maintain an information security governance framework and supporting processes to ensure that the information security strategy is aligned with the goals and objectives of the organization - Obtain commitment from senior management and other stakeholders for the information security program - Define and communicate the roles and responsibilities for information security throughout the organization - Identify internal and external influences to the organization that affect the information security strategy and program - Establish and/or maintain information security policies to guide the development of standards, procedures and guidelines in alignment with enterprise goals and objectives |
| Information Security Incident Management | 30% | - Establish and maintain processes to investigate and document information security incidents - Establish and maintain incident escalation and notification processes - Establish and maintain communication plans and processes to manage communication with internal and external entities - Organize, train and equip teams to effectively respond to information security incidents - Establish and maintain an organizational definition of, and severity hierarchy for, information security incidents - Establish and maintain an incident response plan to ensure an effective and timely response to information security incidents - Test, review and revise the incident response plan - Develop and implement processes to ensure the timely identification of information security incidents |
| Information Security Program Development and Management | 33% | - Integrate information security requirements into organizational processes - Develop and maintain a security awareness, training and education program for all stakeholders - Align the information security program with the operational objectives of other business functions - Identify, acquire and manage information security requirements for internal and external resources (services, partners, and suppliers) - Establish and/or maintain the information security program in alignment with the information security strategy - Monitor and manage the information security program - Establish, communicate and maintain organizational information security standards, guidelines, procedures and other documentation - Establish and maintain information security architectures (people, process, technology) |
CISM日本語 Exam FAQ — Effective Preparation
The ISACA Certified Information Security Manager (CISM日本語版) is ISACA's certification exam for Isaca Certification, at the Manager level. It validates skills employers hire for, which is why it can affect your career and future. Related credentials include CISM.
Files arrive by automatic email within a minute of payment — unlimited installations, and 24/7 customer assisting for any login or downloading issues if nothing shows up within 2 hours. If you fail the corresponding CISM日本語 exam within 60 days of purchase, you have options: a full refund (send a scanned enrollment slip plus the official Score Report PDF within 2 days of the exam; processed within 7 days), waiting for the next updated version free, or changing to two other equal-value dumps free. Excluded: exams within 3 days of purchase, candidate names that don't match the payer, and free or expired products.
To earn the CISM certification, candidates must pass the exam and possess a minimum of five years of information security work experience with a minimum of three years of information security management work experience in three or more of the CISM domains. Substitutions and waivers for general information security experience are available. Vendors revise eligibility rules from time to time, so verify the current requirements on the official page (official CISM日本語 exam page) before booking.
The ISACA Certified Information Security Manager (CISM日本語版) blueprint covers 4 domains — including Information Security Program Development and Management (33%), Information Security Governance (17%), Information Security Incident Management (30%). The weightings tell you where to spend your hours; the complete outline above lists every subtopic.
$575 (Member) / $760 (Non-Member) per attempt, 450 (out of 800) to pass. A retake bills the full fee again, so prepare smartly: work through the 1193 practice questions for the CISM日本語 exam at ValidExam before you book.
240 minutes for 150 questions. Efficient preparation includes pacing: rehearse timed sets until the clock feels manageable, not menacing.
Yes — download the free ISACA Certified Information Security Manager (CISM日本語版) demo and judge the quality before paying. Purchases include 365 days of free updates, with each latest version emailed to you immediately; renew afterward at 50% off.
ISACA Certified Information Security Manager (CISM日本語版) Sample Questions:
情報セキュリティインシデント分類における重大度階層の主要な基準として、以下のうちどれを用いるべきでしょうか?
- A. 根本原因分析結果
- B. 資源の入手可能性
- C. 事業への悪影響
- D. 法的および規制上の要件
Correct Answer: C 🗳️
Explanation: Only visible for ValidExam members. You can sign-up / login (it's free).
ある組織で、フィッシングメールに関連するインシデントが急増しています。根本原因は、ベンダーによるサポートが終了した古いメールフィルタリングシステムです。情報セキュリティマネージャーが最初にとるべき行動は次のうちどれでしょうか?
- A. システムを置き換えるためのビジネスケースを作成する。
- B. ファイアウォール上の送信トラフィックを監視します。
- C. エンドユーザーに対するセキュリティ意識向上策を強化する。
- D. メールシステムを一時的にクラウドプロバイダーにアウトソーシングする。
Correct Answer: A 🗳️
Explanation: Only visible for ValidExam members. You can sign-up / login (it's free).
情報セキュリティ プログラムと組織戦略の整合性を確保するために最も重要なのは次のうちどれですか。
- A. 業界の同業他社とのベンチマーク
- B. 業界で認められたフレームワークの採用
- C. ビジネス固有のリスク要因の特定
- D. 上級管理職からの承認
Correct Answer: D 🗳️
情報セキュリティポリシーの第一の目的は何であるべきか?
- A. 経営陣の期待事項を概説する
- B. セキュリティ手順の詳細
- C. 規制要件を遵守するため
- D. 業界のベストプラクティスとの整合性を確保するため
Correct Answer: A 🗳️
Explanation: Only visible for ValidExam members. You can sign-up / login (it's free).
情報セキュリティインシデントの影響を受けた顧客への連絡において、以下のうちどれを最も重要に含めるべきでしょうか?
- A. 事件に関する技術情報
- B. 漏洩したデータの種類の詳細
- C. 組織にとってのインシデントによるコスト
- D. 攻撃者の身元
Correct Answer: B 🗳️
Explanation: Only visible for ValidExam members. You can sign-up / login (it's free).
Free Demo






