both CISSP and CISM require individuals to have at least 5 years of information security experience, CISM additionally require the individual to have a minimum of 3 years experience