CISSP is a shallow level across a broad spectrum of technical InfoSec domains.
CISM is more focussed on processes to manage risk in the InfoSec arena. CISA is similar but focusses on the audit aspect.
CISSP is good to substantiate other technical skills/certs to show an employer that you are well versed in more than just a single vendor technology stack. CISM is for somebody aiming for, or in a management position (less hands on technically on a day to day basis).