Exam CISM All QuestionsBrowse all questions from this exam
Question 1064

Which of the following is the BEST indication that an information security control is no longer relevant?

    Correct Answer: B

    The best indication that an information security control is no longer relevant is that it does not support a specific business function. Information security controls are implemented to protect business processes and functions. If a control no longer aligns with or supports the business objectives, it has lost its relevance. While cost efficiency, management support, and technology obsolescence are factors to consider, the primary purpose of any control is to protect and enable business functions.

Discussion
bronayOption: B

B. The control doesn't support Business functions

MMK777Option: D

No longer relevant, which means it was relevant before

1899f17Option: B

B. The control does not support a specific business function.

helg420Option: B

also agree with B. Not all controls are related to technology

Der_PhomasOption: B

Agree with B.