CISM Certified Information Security Manager – Question1217

Which of the following is the BEST indication that an information security control is no longer relevant?

A.
Users regularly bypass or ignore the control.
B. The control does not support a specific business function.
C. IT management does not support the control.
D. Following the control costs the business more than not following it.

Correct Answer: B