CISM Exam QuestionsBrowse all questions from this exam

CISM Exam - Question 1068


Which of the following is the BEST indication that an information security control is no longer relevant?

Show Answer
Correct Answer: B

The best indication that an information security control is no longer relevant is that it does not support a specific business function. Information security controls are implemented to protect business processes and functions. If a control no longer aligns with or supports the business objectives, it has lost its relevance. While cost efficiency, management support, and technology obsolescence are factors to consider, the primary purpose of any control is to protect and enable business functions.

Discussion

6 comments
Sign in to comment
bronayOption: B
Apr 27, 2024

B. The control doesn't support Business functions

1899f17
May 28, 2024

B. The control does not support a specific business function.

hargitOption: B
Mar 3, 2025

Not D: technology could stil be used (e.g. old PC in control room etc)

Der_Phomas
May 7, 2024

Agree with B.

helg420Option: B
May 17, 2024

also agree with B. Not all controls are related to technology

MMK777Option: D
Jul 9, 2024

No longer relevant, which means it was relevant before