CISM Information Security Programme Practice Question
An organization uses CIS Controls v8. They are a small business with limited cybersecurity resources. Which implementation group (IG) should they prioritize?
⚠ Common exam trap
CISM often tests the misconception that 'more controls equals better security,' leading candidates to select IG3 as the most comprehensive answer when the question explicitly describes a resource-constrained small business.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
IG1
CIS Controls v8 defines Implementation Group 1 (IG1) as the foundational set of safeguards appropriate for small organizations with limited cybersecurity resources and low data sensitivity. IG1 covers essential hygiene controls (inventory, patching, access control, malware defenses) that provide the highest risk reduction per unit of effort. A small business should implement IG1 first and only progress to IG2/IG3 as resources and risk profile grow.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
All IGs simultaneously
Why it's wrong here
CIS Controls v8 defines IGs as cumulative tiers, so implementing all simultaneously ignores the resource constraints stated in the stem. The groups exist precisely so organisations adopt controls progressively. Attempting all at once suits well-resourced enterprises, not a small business.
- ✗
IG3
Why it's wrong here
IG3 comprises 23 controls including advanced, threat-focused safeguards for organisations with dedicated security teams and mature processes. A small business with limited resources cannot implement them all. IG3 suits large enterprises handling sensitive data with specialised staff.
- ✓
IG1
Why this is correct
IG1 defines the foundational cyber hygiene safeguards achievable with limited resources and no dedicated security staff, matching the small business constraint. Prioritising IG1 addresses the most prevalent attack vectors first, providing essential protection before progressing to IG2 or IG3.
- ✗
IG2
Why it's wrong here
IG2 adds 74 controls covering 11 functional areas, demanding documented processes and centralised management a small business with limited resources cannot sustain. IG2 suits organisations with moderate resources and some dedicated security staff, not the smallest enterprises.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.