Courseiva

CISM Information Security Programme Practice Question

A security manager is selecting a controls framework for a new organization. Which framework provides the most granular control families and is widely used for US federal agencies?

⚠ Common exam trap

CISM often tests the distinction between frameworks based on granularity and intended audience; candidates may incorrectly choose ISO 27001 because it is widely known, but the key differentiator is that NIST SP 800-53 is specifically required for US federal agencies and offers more detailed control families.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

NIST SP 800-53

NIST SP 800-53 is the correct answer because it provides the most granular control families (20 families, over 1,000 controls) and is mandated for US federal agencies under FISMA. Its control catalog is organized into detailed families such as AC (Access Control), AU (Audit and Accountability), and CM (Configuration Management), each with specific control enhancements. This level of granularity and its federal adoption make it the best fit for the scenario.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    CIS Controls v8

    Why it's wrong here

    CIS Controls v8 provides 18 prioritised safeguards, not granular control families, and carries no US federal mandate. It is tempting because its implementation groups give small teams a pragmatic starting sequence, which suits organisations lacking the resources to adopt a full federal catalogue.

  • ✗

    ISO 27001 Annex A

    Why it's wrong here

    ISO 27001 Annex A lists 93 controls in four themes, far fewer and less granular than NIST SP 800-53's control families, and it is an international standard rather than a US federal mandate. It is tempting because certification to it demonstrates a working ISMS, which suits commercial assurance.

  • ✓

    NIST SP 800-53

    Why this is correct

    NIST SP 800-53 provides granular control families and is mandated for US federal agencies, satisfying the stem's federal and granularity constraints. Its catalogue spans 20 control families with detailed enhancements, exceeding ISO 27002's breadth and CIS Controls' prioritised subset.

  • ✗

    COBIT 2019

    Why it's wrong here

    COBIT 2019 is a governance and management framework for enterprise IT, not a catalogue of granular control families, and it is not the US federal standard. It is tempting because it maps well to audit and board-level oversight, where aligning IT objectives with business goals is the actual requirement.

About these practice questions

One of 924 original CISM practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.