Courseiva

CISM Information Security Programme Practice Question

An organization uses CIS Controls v8. They are a small business with limited cybersecurity resources. Which implementation group (IG) should they prioritize?

⚠ Common exam trap

CISM often tests the misconception that 'more controls equals better security,' leading candidates to select IG3 as the most comprehensive answer when the question explicitly describes a resource-constrained small business.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

IG1

CIS Controls v8 defines Implementation Group 1 (IG1) as the foundational set of safeguards appropriate for small organizations with limited cybersecurity resources and low data sensitivity. IG1 covers essential hygiene controls (inventory, patching, access control, malware defenses) that provide the highest risk reduction per unit of effort. A small business should implement IG1 first and only progress to IG2/IG3 as resources and risk profile grow.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    All IGs simultaneously

    Why it's wrong here

    CIS Controls v8 defines IGs as cumulative tiers, so implementing all simultaneously ignores the resource constraints stated in the stem. The groups exist precisely so organisations adopt controls progressively. Attempting all at once suits well-resourced enterprises, not a small business.

  • ✗

    IG3

    Why it's wrong here

    IG3 comprises 23 controls including advanced, threat-focused safeguards for organisations with dedicated security teams and mature processes. A small business with limited resources cannot implement them all. IG3 suits large enterprises handling sensitive data with specialised staff.

  • ✓

    IG1

    Why this is correct

    IG1 defines the foundational cyber hygiene safeguards achievable with limited resources and no dedicated security staff, matching the small business constraint. Prioritising IG1 addresses the most prevalent attack vectors first, providing essential protection before progressing to IG2 or IG3.

  • ✗

    IG2

    Why it's wrong here

    IG2 adds 74 controls covering 11 functional areas, demanding documented processes and centralised management a small business with limited resources cannot sustain. IG2 suits organisations with moderate resources and some dedicated security staff, not the smallest enterprises.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.