Here's one:
http://www.cisco.com/warp/public/110/pixcryaaa52.shtml#howto2
Basically isakmp policy is not configured per group, the VPN client will run through each policy from the top down until it finds a match, you can't have one group use this policy and one group use that policy. Same goes for dynamic-crypto maps and the transform set.
Access-lists for split tunnelling can certainly be dofferent, as can address pools and WINS/DNS servers.