CISM Exam QuestionsBrowse all questions from this exam

CISM Exam - Question 1064


Which of the following is the BEST indication that an information security control is no longer relevant?

Show Answer
Correct Answer: BD

The best indication that an information security control is no longer relevant is that it does not support a specific business function. Information security controls are implemented to protect business processes and functions. If a control no longer aligns with or supports the business objectives, it has lost its relevance. While cost efficiency, management support, and technology obsolescence are factors to consider, the primary purpose of any control is to protect and enable business functions.

Discussion

5 comments
Sign in to comment
bronayOption: B
Apr 27, 2024

B. The control doesn't support Business functions

Der_PhomasOption: B
May 7, 2024

Agree with B.

helg420Option: B
May 17, 2024

also agree with B. Not all controls are related to technology

1899f17Option: B
May 28, 2024

B. The control does not support a specific business function.

MMK777Option: D
Jul 9, 2024

No longer relevant, which means it was relevant before