CISM Information Security Programme Practice Question
In designing a security programme for a mid-sized enterprise, the CISO is deciding which security framework to adopt for control selection. Which of the following frameworks is specifically structured around implementation groups (IG1, IG2, IG3) to help organizations prioritize controls based on risk and maturity?
⚠ Common exam trap
CISM often tests the confusion between frameworks that provide control catalogs (ISO 27001, NIST 800-53) and those that offer implementation groups for prioritization (CIS Controls v8).
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CIS Controls v8
CIS Controls v8 is specifically structured around Implementation Groups (IG1, IG2, IG3) to help organizations prioritize controls based on risk and maturity. IG1 is for small organizations with limited resources, IG2 for mid-sized with more risk, and IG3 for mature organizations facing advanced threats. This makes it uniquely suited for the scenario described.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
CIS Controls v8
Why this is correct
CIS Controls v8 uniquely organises its 18 controls into IG1, IG2 and IG3, letting organisations select safeguards matching their risk profile and maturity. No other listed framework uses implementation groups as its prioritisation structure, satisfying the stem's specific requirement.
- ✗
ISO 27001 Annex A
Why it's wrong here
ISO 27001 Annex A lists 93 controls in thematic clauses with no implementation-group tiering, so it cannot prioritise by IG1/IG2/IG3 maturity. It is tempting as a widely recognised certifiable standard, and it would be correct when seeking an auditable ISMS control catalogue rather than tiered prioritisation.
- ✗
NIST SP 800-53
Why it's wrong here
NIST SP 800-53 supplies a broad control catalogue organised by control families and baselines, not by implementation groups; IG1–IG3 belong to the CIS Critical Security Controls. It is tempting because 800-53 is a legitimate control-selection framework, and would be correct where a US federal baseline or FedRAMP-style control mapping is required.
- ✗
COBIT 2019
Why it's wrong here
COBIT 2019 organises governance and management objectives across five domains, not implementation groups, so it cannot tier controls by IG1/IG2/IG3. It is tempting as a mature IT governance framework, and it would be correct for aligning IT objectives with enterprise governance rather than maturity-based control prioritisation.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISACA exam blueprint
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.